Earlier quoted context omitted.
Misappropriating trade secrets for financial gain is a punishable offense, and this data would qualify as a trade secret, at least for as long as it's not general knowledge to everyone or it has yet to be reverse-engineered. Aside from that, much of the data in these files has standard copyright and patent concerns.
OK then, out of curiosity, what are the relevant laws being broken here?
20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
311–320 of 476 posts
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#312Earlier quoted context omitted.
So much this. My company just got done shelling out a ton of money for some asshat to tell me that we can't use http on a dev server.
It's worse when the asshat convinces your manager that every internal site, whether dev or not needs https. Certs everywhere. Our team spends a decent % of our time generating and managing certs...
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#313Earlier quoted context omitted.
A manufacturer wanted to upgrade one of their equipment lines to be more modern. The developers of the original product, both hardware and software, were no longer with the company. Since they just wanted to add some new features on top and present a better rack-based interface to the user, they decided to build a bigger box, put one of the old devices inside the box, then put a modern PC in there, and just link the…
Reminds me a little of a place I worked. They sold very expensive devices that were actually an off-the-shelf 1U PC with custom software (which provided the real value). The problem — and this dates it — was that the PCs had a game port¹, which gave away that this custom hardware was really just a regular consumer PC. So they had some fancy plastic panels made to clip on the front and hide the game port. ¹ https://en…
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#314Earlier quoted context omitted.
So much this. My company just got done shelling out a ton of money for some asshat to tell me that we can't use http on a dev server.
It's worse when the asshat convinces your manager that every internal site, whether dev or not needs https. Certs everywhere. Our team spends a decent % of our time generating and managing certs...
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#315Anybody else wondering at the rate of bad news around Intel at this moment? Like, is someone after them or is this just bad luck?
Personally it seems more like complacency and cultural rot has caught up to them than any bad actor - excluding their own management chasing ego gratification or short term profits. Falling behind AMD in so many metrics when they were previously often a second-best rival screams that they need to get their shit together.
Intel needs to kick off a skunk works that basically gets funded well enough to find a new way.
If they do it now, some space could get really interesting again.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#316Earlier quoted context omitted.
I don't believe this is accurate or in any way obvious even if this is the stance the courts would ultimately take. These files were downloaded from a publicly available CDN server discovered while browsing the internet. No authorization mechanisms were bypassed, no computer systems were hacked. These files are the result of a GET request to an Akamai server that happened to be hosting the files. Despite how this wil…
If someone leaves their door unlocked and open it doesn't mean I have a right to walk in and take what I want.
Physical analogies break down.
Truth is, this info was out there for anyone to copy, and who ever did that is definitely guilty of something and or liable.
It will be tough to make passers by into criminals here. They aren't.
Keeping secrets is hard. Should be.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#317Earlier quoted context omitted.
This 100%. I recall many a fun night at $BIGCORP burning the midnight oil, receiving the warning emails that my "unauthorised software" had been reported to my manager, and that it had been quarantined away for my own safety and convenience. Given that $BIGCORP was a tech firm my manager would be intensely delighted that they would receive regular midnight notifications that I was doing my job. Whatever that damn thi…
Windows development seems to be fun as of recently. Didn't touch it for couple of decades. Sometimes I think that modern Windows is a nice platform already, even comfortable. (Like, you know, C++17 is very unlike C++98.) But then I'm reminded of the necessity to run an antivirus in front of it in a corporate environment.
Yes such a thing exists... https://www.mcafee.com/enterprise/en-us/products/virusscan-e...
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#318Earlier quoted context omitted.
OK then, out of curiosity, what are the relevant laws being broken here?
Wire fraud and, trade secrets acts are the two that are usually applied in these cases. https://en.wikipedia.org/wiki/Mail_and_wire_fraud https://en.wikipedia.org/wiki/Defend_Trade_Secrets_Act
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#319Earlier quoted context omitted.
for not using gmail? The hooked me in school
He means there used to be a time when people would mail binaries to each other more often, before they got too big and DRM'ed for that.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#320Earlier quoted context omitted.
You just gave them money. They didn't coerce you. It would be different if they flashed a weapon.
It's a fictitious example. I didn't say there was no weapon, nor said it was definitely theft. The point is that submitting a GET request in a public setting does not mean no crime. Coercion can be the difference between asking for money and theft. In the case of this intel data, it was clearly coerced from a server - it's not like it was linked on Google, they had to specially craft URLs to coerce the data out.
There is zero theft in this discussion.
One could argue there was infringement, and that argument is very difficult to make without breaking the Internet for everyone just because someone with deep pockets failed.
Coercion involves, at the core, an act of agency performed to the intent of someone else, who is not the agent, actor.
Bad practice does not support coercion at all.
I wonder whether that word even applies to entities lacking agency.
Servers are automatons. They do not make value judgements and or creative acts of agency of any kind.
We need these things as a basis for coersion.
There are lots of things not indexed by Google and it is dangerous to imply people are somehow wrong when data is accessed sans a Google index.
Security by obscurity does not make sense. This mess is part of why.