Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

151–160 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#151
post #17
post #16

Is releasing this legal? It seems like this person isn't really disguising their identity or concerned about breaking the law. In their profile they even seem to brag about leaking company's code.

Of course it's not legal. This is exfiltrated intellectual property being shared without license.

For this code it might be export-controlled as well. Many things in Intel are export controlled.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#152
post #41

Fingers crossed that this will enable some smart person to completely disable the management engine.

AFAIK the ME is required to initialize the processor so it can never be completely disabled. The best you could do is remove any code beyond necessary initialization which has mostly already been done by me_cleaner.

Or buy a laptop from a manufacturer with the ME inoperable.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#153
post #75

This is more embarrassing than harmful. Having worked at companies like intel, it's not really that damaging leaking some of this IP - the worst that happens is some open source project gets slightly better or you have a few more bugs (not that Intel are lacking in that area). The second we see internal marketing, pricing & road map slides- that's when you know they're in real trouble.

No the worst is it there is some dirt and people find it like:

- copyright infringement

- patent infringement

- actual backdoors (the word backdoor does appear but there are many ways how it can already without they being a backdoor got spying including bad naming sense of engineers and code used during prototyping only

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#158
post #33

Earlier quoted context omitted.

... They're claiming it came from an NDA'd source of IP that's shared with customers. Given that it _appears_ like there are backdoors in this Firmware code, we can conclude that if there are such backdoors then they were shared with numerous customers. That really doesn't improve the optics of the breach.

Alternately, as others have noted, it could be overloaded nomenclature and doesn't actually indicate a backdoor. Which would be an excellent reason for them to feel comfortable sharing said 'backdoors' with their customers.

It it is actually a backdoor but only gets put on prototypes/engineering samples or similar.

Or maybe some well documented Intel management features need to backdoor there own security mechanisms to work.

Or ...

Well the point is it's a starting point for someone dissecting the data but not much more.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#159

Earlier quoted context omitted.

Usually this. Or in my workplace, an image. Antivirus are some crazy shit that may trigger on any random action and will teach people to follow the most unsafe procedures without questioning, so they can get anything done.

I've heard it put this way: If you force users to trade convenience for security, they will find a way to obtain convenience at the expense of security.

If you make it harder for people to do the right thing than the wrong thing, they will choose the wrong thing.

This has been brought up a million times in the context of DRM, but it is true in the general case as well.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#160

Earlier quoted context omitted.

Because until this thing gets diffused and dissected by everyone and their mothers, the law is likely to view it as publication of confidential trade secrets, and people who can be confirmed to be spreading such things can get federal time, e.g. [1] for example. Using a VPN is the barest of mechanisms to try to obscure your identity to avoid this sort of punishment. [1] https://www.wsj.com/articles/SB1000142405297020…

Right but if you just download without seeding, no crime is being committed, yes? So seems like the barest you can do is "disable seeding", not "use a VPN".

IANAL and you should probably contact yours about such things but a straightforward reading suggests that because you knew you were downloading something likely illegally gotten, you are in fact on the hook for downloading it.

    “Misappropriation” means: 

      (i) acquisition of a trade secret of another by a person who knows or has
        reason to know that the trade secret was acquired by improper means; or
      (ii) disclosure or use of a trade secret of another without express or
        implied consent by a person who 
        (A) used improper means to acquire knowledge of the trade secret; or 
        (B) at the time of disclosure or use knew or had reason to know that
          his knowledge of the trade secret was 
          (I) derived from or through a person who has utilized improper means 
            to acquire it; 
          (II) acquired under circumstances giving rise to a duty to maintain
            its secrecy or limit its use; or 
          (III) derived from or through a person who owed a duty to the person
            seeking relief to maintain its secrecy or limit its use; or 
        (C) before a material change of his position, knew or had reason to
          know that it was a trade secret and that knowledge of it had been
          acquired by accident or mistake.
Post reply on HN