Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

211–220 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#211

Earlier quoted context omitted.

If you make it harder for people to do the right thing than the wrong thing, they will choose the wrong thing. This has been brought up a million times in the context of DRM, but it is true in the general case as well.

I could be mistaken on this, but wasn't this basically the sales pitch for Spotify? Basically saying "you'll never get rid of piracy, but you can compete with it".

Not sure about Spotify, but I know gabe newell had famously made basically this argument, in regards to steam's success

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#212

Earlier quoted context omitted.

But what if manhole is just mankind hole? (It probably isn't, I didn't look it up). Man doesn't always mean male, or does it?

Viewpoints can be encoded in language https://en.wikipedia.org/wiki/Male_as_norm

[deleted]

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#213

Earlier quoted context omitted.

But what if manhole is just mankind hole? (It probably isn't, I didn't look it up). Man doesn't always mean male, or does it?

Viewpoints can be encoded in language https://en.wikipedia.org/wiki/Male_as_norm

> In practice, grammatical gender exhibits a systematic structural bias that has made masculine forms the default for generic, non-gender-specific contexts.

many instances of this are simply an artifact of 'man' previously being an un-gendered term. but that fact is much harder to build group cohesion around than grievance.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#214

Earlier quoted context omitted.

Misappropriating trade secrets for financial gain is a punishable offense, and this data would qualify as a trade secret, at least for as long as it's not general knowledge to everyone or it has yet to be reverse-engineered. Aside from that, much of the data in these files has standard copyright and patent concerns.

Wouldn't financial gain limit it to essentially their competitors? Which renders that part irrelevant and is kind of a "no shit" to anyone actually working in processors not to include their stuff in there.

Also: financial damage

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#215

Earlier quoted context omitted.

You don’t actually need to listen to auditors. People like you (who can’t be bothered to argue because it’s apparently too hard) is the reason that smartass is still selling their services.

So much this. My company just got done shelling out a ton of money for some asshat to tell me that we can't use http on a dev server.

It's worse when the asshat convinces your manager that every internal site, whether dev or not needs https. Certs everywhere. Our team spends a decent % of our time generating and managing certs...

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#216
post #198
post #17

Earlier quoted context omitted.

Of course it's not legal. This is exfiltrated intellectual property being shared without license.

I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…

Verizon and US courts would disagree with you.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#217
post #17

Earlier quoted context omitted.

Of course it's not legal. This is exfiltrated intellectual property being shared without license.

Which country laws does apply? Is it really illegal to share this in the whole world? Im not so sure about that.

Most western countries agree that the concept of ‘intellectual property’ is a good thing and afford protection, or else society disincentivizes innovation due to game theoretic tragedy of the commons-type reasons.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#218
post #198

Earlier quoted context omitted.

I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…

Verizon and US courts would disagree with you.

Links? I'm curious about existing case law.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#219
post #10
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

The shared stupid passwords like this that I've seen/had to use in my career would utterly shock you. Like hunter2 levels of shock.

  > Like ******* levels of shock.
What do you mean with 7 star levels?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#220
post #6

The advice to try a password of “Intel123” on any protected files says it all. This organisation genuinely deserves whatever is coming for them.

In my experience password protected files are often password protected for obscure reasons which have nothing to do with the intent of keeping them secret, like: - prevent anti virus from messing with it - keep to some obscure regulations wrt. Contacts or law, where is enough if you can argue the data was encrypted.

If you make zip files in a company, there is never a repository of passwords, because that would be insecure, ergo zip files with other passwords usually are not easy to unzip after 5-10 years when the owner is dead/gone and the passwords are lost.
Post reply on HN