Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

311–320 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#311
post #106

Earlier quoted context omitted.

Misappropriating trade secrets for financial gain is a punishable offense, and this data would qualify as a trade secret, at least for as long as it's not general knowledge to everyone or it has yet to be reverse-engineered. Aside from that, much of the data in these files has standard copyright and patent concerns.

OK then, out of curiosity, what are the relevant laws being broken here?

Wire fraud and, trade secrets acts are the two that are usually applied in these cases.

https://en.wikipedia.org/wiki/Mail_and_wire_fraud

https://en.wikipedia.org/wiki/Defend_Trade_Secrets_Act

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#312
post #215

Earlier quoted context omitted.

So much this. My company just got done shelling out a ton of money for some asshat to tell me that we can't use http on a dev server.

It's worse when the asshat convinces your manager that every internal site, whether dev or not needs https. Certs everywhere. Our team spends a decent % of our time generating and managing certs...

I am confused. Isn't that easily automated?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#313
post #282

Earlier quoted context omitted.

A manufacturer wanted to upgrade one of their equipment lines to be more modern. The developers of the original product, both hardware and software, were no longer with the company. Since they just wanted to add some new features on top and present a better rack-based interface to the user, they decided to build a bigger box, put one of the old devices inside the box, then put a modern PC in there, and just link the…

Reminds me a little of a place I worked. They sold very expensive devices that were actually an off-the-shelf 1U PC with custom software (which provided the real value). The problem — and this dates it — was that the PCs had a game port¹, which gave away that this custom hardware was really just a regular consumer PC. So they had some fancy plastic panels made to clip on the front and hide the game port. ¹ https://en…

I remember early in my career I came across a Unisys “mainframe”, which was literally a Dell box with a custom bezel, clustered with a few other nodes with a Netgear switch.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#314
post #215

Earlier quoted context omitted.

So much this. My company just got done shelling out a ton of money for some asshat to tell me that we can't use http on a dev server.

It's worse when the asshat convinces your manager that every internal site, whether dev or not needs https. Certs everywhere. Our team spends a decent % of our time generating and managing certs...

Not quite so crazy now that everyone's working from home, right? Unless you also use a VPN?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#315
post #113

Anybody else wondering at the rate of bad news around Intel at this moment? Like, is someone after them or is this just bad luck?

Personally it seems more like complacency and cultural rot has caught up to them than any bad actor - excluding their own management chasing ego gratification or short term profits. Falling behind AMD in so many metrics when they were previously often a second-best rival screams that they need to get their shit together.

This. Inertia, tech debt, a less nimble culture all add up.

Intel needs to kick off a skunk works that basically gets funded well enough to find a new way.

If they do it now, some space could get really interesting again.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#316
post #290
post #198

Earlier quoted context omitted.

I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…

If someone leaves their door unlocked and open it doesn't mean I have a right to walk in and take what I want.

This is more like leaving it on the street, mixed in with a lot of other free stuff.

Physical analogies break down.

Truth is, this info was out there for anyone to copy, and who ever did that is definitely guilty of something and or liable.

It will be tough to make passers by into criminals here. They aren't.

Keeping secrets is hard. Should be.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#317
post #298

Earlier quoted context omitted.

This 100%. I recall many a fun night at $BIGCORP burning the midnight oil, receiving the warning emails that my "unauthorised software" had been reported to my manager, and that it had been quarantined away for my own safety and convenience. Given that $BIGCORP was a tech firm my manager would be intensely delighted that they would receive regular midnight notifications that I was doing my job. Whatever that damn thi…

Windows development seems to be fun as of recently. Didn't touch it for couple of decades. Sometimes I think that modern Windows is a nice platform already, even comfortable. (Like, you know, C++17 is very unlike C++98.) But then I'm reminded of the necessity to run an antivirus in front of it in a corporate environment.

We have to have antivirus on our Linux computers for compliance.

Yes such a thing exists... https://www.mcafee.com/enterprise/en-us/products/virusscan-e...

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#318
post #106

Earlier quoted context omitted.

OK then, out of curiosity, what are the relevant laws being broken here?

Wire fraud and, trade secrets acts are the two that are usually applied in these cases. https://en.wikipedia.org/wiki/Mail_and_wire_fraud https://en.wikipedia.org/wiki/Defend_Trade_Secrets_Act

[deleted]

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#319

Earlier quoted context omitted.

for not using gmail? The hooked me in school

He means there used to be a time when people would mail binaries to each other more often, before they got too big and DRM'ed for that.

There was also a time when alt.binaries was a thing (technically not email, but usenet is pretty similar)

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#320
post #260

Earlier quoted context omitted.

You just gave them money. They didn't coerce you. It would be different if they flashed a weapon.

It's a fictitious example. I didn't say there was no weapon, nor said it was definitely theft. The point is that submitting a GET request in a public setting does not mean no crime. Coercion can be the difference between asking for money and theft. In the case of this intel data, it was clearly coerced from a server - it's not like it was linked on Google, they had to specially craft URLs to coerce the data out.

For there to be theft a property owner has to lose their property and or use of said property.

There is zero theft in this discussion.

One could argue there was infringement, and that argument is very difficult to make without breaking the Internet for everyone just because someone with deep pockets failed.

Coercion involves, at the core, an act of agency performed to the intent of someone else, who is not the agent, actor.

Bad practice does not support coercion at all.

I wonder whether that word even applies to entities lacking agency.

Servers are automatons. They do not make value judgements and or creative acts of agency of any kind.

We need these things as a basis for coersion.

There are lots of things not indexed by Google and it is dangerous to imply people are somehow wrong when data is accessed sans a Google index.

Security by obscurity does not make sense. This mess is part of why.

Post reply on HN