Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

121–130 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#121

In what ways can an end user of intel processor expect to benefit from this? I'm guessing none, since ever consumer interface is already a standard ... Can anybody chime in?

While it doesn't mean it will happen, depending on what is leaked now and in the future, possibilities include:

1. Verify that debug features that are remotely exploitable are actually disabled in consumer releases of their hardware.

2. Re-implement proprietary parts of the boot sequence, such as activating memory controllers, in an open and public manner that can be more easily looked over for flaws, security and otherwise.

3. Modify parameters and tweak hardware for additional stability or performance enhancements, especially undocumented or disabled(on lower graded chips of the same architecture) aspects of the hardware that may be present.

On the other hand barriers include legal issues depending on what country people working on these originate from, ethical issues, and even industry barring, and this is not exhaustive. Consumers, especially consumers in countries not concerned about the legal aspects will likely gain the most advantages, if any are present.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#122
post #11

At a previous workplace we had a few places in the code which used the word backdoor. It was not an actual backdoor though, but merely a debugging server that could be enabled and allowed you to inspect internal state during runtime. At some point I removed the word backdoor, fearing it would get to a customer or during an audit someone would misunderstand. :|

I worked at a place where IT had an admin user on every machine named "Backdoor". I opened a ticket when I noticed it, which was promptly closed explaining that it was normal.

The same place had a boot script on every computer that wrote to a network-mounted file. Everyone had read permissions to it (and probably write, but I didn't test) and the file contained user names, machine names, and date-times of every login after boot for everyone on the domain going back 5 years. I opened a ticket for that, which was never addressed.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#123
post #14

Someone have a mirror? Seems the actual files are here: https://t.me/exconfidential/590 Edit: files are here https://mega.nz/folder/CV91XLBZ#CPSDW-8EWetV7hGhgGd8GQ or magnet:?xt=urn:btih:38f947ceadf06e6d3ffc2b37b807d7ef80b57f21

I'd assume spreading this is not legal?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#124
post #16

Is releasing this legal? It seems like this person isn't really disguising their identity or concerned about breaking the law. In their profile they even seem to brag about leaking company's code.

Stealing it is probably illegal, and there’s a copyright and export regulations argument to be made around copying it.

However, my understanding of the law is that, once secrets are made public, further distributing the secrets is not illegal.

So, republishing it is probably not more illegal than running a torrent of a Hollywood movie and an Ubuntu ISO (which can run afoul of export regulations).

Note: I’m not a lawyer, and if what I said was true in practice, Julian Assange / Wikileaks would have nothing to fear from the law.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#125
post #71
post #54

Earlier quoted context omitted.

The countries of origin of the peers downloading that torrent is pretty cool to see. A fairly broad cross-section of the world.

Not reliable. Most people torrenting this are hopefully using a vpn.

Why?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#126
post #48

Earlier quoted context omitted.

It will be more or less impossible to prove or disprove that anyone obtained some crucial information from there. The info will always somehow make it's way into the places it's needed eventually.

It doesn’t matter if it’s provable or not, most developers won’t risk it especially if they want to keep their jobs or be hireable. If you review the content and publish say a blog post, even without legal repercussions it can impact your ability to be hired in the future since everything you do from that point can be tainted. So if you do look you should keep it quite or publish it under a pen name that you can’t ev…

Say we use the Microsoft Windows code that got leaked, was anyone black listed for that?

Also, I would assume other processor companies hire people from other processor companies and everyone all wants the best, most of the basic knowledge would have already made it's way to AMD and other companies.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#127
post #71
post #54

Earlier quoted context omitted.

The countries of origin of the peers downloading that torrent is pretty cool to see. A fairly broad cross-section of the world.

Not reliable. Most people torrenting this are hopefully using a vpn.

Or a SeedBox.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#128

Earlier quoted context omitted.

Gmail doesn't seem to like archives it can't open :/

Ah, the halcyon days of merely changing the file extension from .exe to .txt...

This brings back happy memories of a college (senior high for the Americans in the audience) computing teacher finding a friend and I had been writing irritating malware instead of doing actual work, and his only comment being “if you’re going to email that to yourself change the extension so it doesn’t get flagged for IT support”.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#129
post #6

The advice to try a password of “Intel123” on any protected files says it all. This organisation genuinely deserves whatever is coming for them.

It’s mentioned in the Twitter thread that at least some of the files have a password of “I accept” instead. That leads me to believe that the primary purpose might just be to indicate agreement to an NDA.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#130
post #85

Earlier quoted context omitted.

How easy is it to use me_cleaner? Last time I looked it required some wiring and a Raspberry Pi.

Quite straightforward, I used a ch341A SPI programmer. Just make sure you take multiple copies of your original ROM image and compare the hashes of them to make sure there was no screwup. It took me about 10 minutes to do my ThinkPad. All I lost was some enhanced integrated GPU power management and integrated thermal management, but I use a userland fan control program anyhow.

How much did it cost? Everything
Post reply on HN