Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

251–260 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#251
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

No one who knows what they're doing uses zip passwords as security. The passwords are probably there for other reasons.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#252
Any IP lawyers in the house willing to speculate on how this is going to go down? Intel surely isn't going to let this stand, and the (Swiss) leaker is being completely open about their identity. What's the legal action going to look like?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#253
post #20

Earlier quoted context omitted.

Also, the passwords are listed in docs that appear to be alongside the encrypted files. That's a bit like leaving the keys to your house _on top_ of your front doormat.

It's kinda like hiring a security guard for insurance purposes, even though they have strict instructions to never do anything, under any circumstances, other than call emergency services.

To be fair having someone aware and around to watch and phone emergency services has a use.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#254
post #198
post #17

Earlier quoted context omitted.

Of course it's not legal. This is exfiltrated intellectual property being shared without license.

I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…

That’s a very weak argument. If I’m walking down the street at night and somebody comes up to me and says “GET /money”, I may respond with an HTTP 200, but that doesn’t mean the person didn’t just steal from me.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#255
post #21

Earlier quoted context omitted.

Yes - but not for hostile purposes, but because your own company's antivirus won't let you mail an executable to a colleague.

In February, I e-mailed a python script to one of our developers to help debug an issue with their SSL configuration. Two days ago, I needed the script again but couldn't find it. Went to our e-mail thread and it said "the following potentially malicious attachments were blocked", showing mine, but... even from my outgoing mailbox? That seems ridiculous and problematic, considering that it sent fine at the time. I kn…

This has happened to me with gmail. Zipfiles I had sent in the past are no longer allowed to be downloaded from my sent items folder through the standard interface.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#256
post #198
post #17

Earlier quoted context omitted.

Of course it's not legal. This is exfiltrated intellectual property being shared without license.

I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…

You have a lot of faith in how technically versed the law and courts are on these topics - because they sure haven't kept up with the times. And even if they were willing to split hairs over these technical details:

No civilian will agree with you that just because technically you could slip through several doors that happened to be not locked and got helpful advice from a neighbor, it doesn't mean that whatever you found behind those doors was "public" just because you didn't have to pick locks. Or that the photos you took of private company documents by social engineering your way inside must clearly be unsecured and publicly distributable because "they were given to me when I asked for them".

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#257

Earlier quoted context omitted.

If you make it harder for people to do the right thing than the wrong thing, they will choose the wrong thing. This has been brought up a million times in the context of DRM, but it is true in the general case as well.

I could be mistaken on this, but wasn't this basically the sales pitch for Spotify? Basically saying "you'll never get rid of piracy, but you can compete with it".

This was also a sales pitch for Steam – especially in developing countries where the whole concept of paying for non-physical things was a hard sell.

(Though in this case it wasn't just competition – access to official servers in online games was something that was often not pirateable.)

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#258
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

A company I know insists on rotating passwords fairly often. Everybody just increases the number at the end of their favourite password, i. e. intel1255

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#259

This kid has been posting these for fame (it's the same guy that posted the Daimler leak). I guess it's all fun and games until he finds himself in prison

I'm not sure you can even consider it "breaking in", it's more like tweeting that under intel.com/super-secret url you can see some internal, secret documents.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#260
post #198

Earlier quoted context omitted.

I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…

That’s a very weak argument. If I’m walking down the street at night and somebody comes up to me and says “GET /money”, I may respond with an HTTP 200, but that doesn’t mean the person didn’t just steal from me.

You just gave them money. They didn't coerce you. It would be different if they flashed a weapon.
Post reply on HN