> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…
20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
251–260 of 476 posts
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#252Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#253Earlier quoted context omitted.
Also, the passwords are listed in docs that appear to be alongside the encrypted files. That's a bit like leaving the keys to your house _on top_ of your front doormat.
It's kinda like hiring a security guard for insurance purposes, even though they have strict instructions to never do anything, under any circumstances, other than call emergency services.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#254Earlier quoted context omitted.
Of course it's not legal. This is exfiltrated intellectual property being shared without license.
I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#255Earlier quoted context omitted.
Yes - but not for hostile purposes, but because your own company's antivirus won't let you mail an executable to a colleague.
In February, I e-mailed a python script to one of our developers to help debug an issue with their SSL configuration. Two days ago, I needed the script again but couldn't find it. Went to our e-mail thread and it said "the following potentially malicious attachments were blocked", showing mine, but... even from my outgoing mailbox? That seems ridiculous and problematic, considering that it sent fine at the time. I kn…
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#256Earlier quoted context omitted.
Of course it's not legal. This is exfiltrated intellectual property being shared without license.
I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…
No civilian will agree with you that just because technically you could slip through several doors that happened to be not locked and got helpful advice from a neighbor, it doesn't mean that whatever you found behind those doors was "public" just because you didn't have to pick locks. Or that the photos you took of private company documents by social engineering your way inside must clearly be unsecured and publicly distributable because "they were given to me when I asked for them".
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#257Earlier quoted context omitted.
If you make it harder for people to do the right thing than the wrong thing, they will choose the wrong thing. This has been brought up a million times in the context of DRM, but it is true in the general case as well.
I could be mistaken on this, but wasn't this basically the sales pitch for Spotify? Basically saying "you'll never get rid of piracy, but you can compete with it".
(Though in this case it wasn't just competition – access to official servers in online games was something that was often not pirateable.)
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#258> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#259This kid has been posting these for fame (it's the same guy that posted the Daimler leak). I guess it's all fun and games until he finds himself in prison
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#260Earlier quoted context omitted.
I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…
That’s a very weak argument. If I’m walking down the street at night and somebody comes up to me and says “GET /money”, I may respond with an HTTP 200, but that doesn’t mean the person didn’t just steal from me.