Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

321–330 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#321
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

Another large tech company I used to work for commonly used an only-slightly more complex password

I know a brand-name healthcare company that uses Passw0rd for its internal WiFi, which is easily reachable from an interstate rest area.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#322

Earlier quoted context omitted.

Exploration of public areas isn't illegal. There's no law mandating that viewing a website though the browser is legal, and any other means not. Techies legitimately access websites in all kinds of programmatic ways. Intel made their data publicly available. That it wasn't accidental doesn't change that.

Opening unlocked doors, entering and removing property is generally considered to be theft. The key here is that these services were not advertising their presence.

Where are the locks?

There are often ways to beaches and other spaces unadvertised, but otherwise OK to use.

Sure looks to me like a potential landmine for people. Bad practice with big pockets should still just be bad practice with the same consequences for all who don't bother with better practices.

There was no lock on this at all.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#323
post #20

Earlier quoted context omitted.

Also, the passwords are listed in docs that appear to be alongside the encrypted files. That's a bit like leaving the keys to your house _on top_ of your front doormat.

It's kinda like hiring a security guard for insurance purposes, even though they have strict instructions to never do anything, under any circumstances, other than call emergency services.

It's kinda like hiring a security guard for insurance purposes, even though they have strict instructions to never do anything, under any circumstances, other than call emergency services.

I see you've worked in retail.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#324

Earlier quoted context omitted.

Exploration of public areas isn't illegal. There's no law mandating that viewing a website though the browser is legal, and any other means not. Techies legitimately access websites in all kinds of programmatic ways. Intel made their data publicly available. That it wasn't accidental doesn't change that.

Opening unlocked doors, entering and removing property is generally considered to be theft. The key here is that these services were not advertising their presence.

Theft requires property owners to be denied their property or the use of it.

That did not happen here. Theft is not part of the discussion.

Infringement could be, and is at least the right language for the discussion.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#325
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

at my first job they used a similar password as their go-to "temporary" password for users etc. I found later when I got to work with the users that they rarely changed this password even when "forced" to, and in many cases had it up on post-its next to their monitor.

and in many cases had it up on post-its next to their monitor.

These days a post it is probably the best way to secure your password.

99.9999999% of password hacks come over the wire now, from people in other cities, states, or nations. If someone is in your building, in front of the computer, even without the post-it, you're probably toast.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#326

Earlier quoted context omitted.

Once I got a complaint from a security auditor that some code was using MD5. It wasn’t being used for any security purpose, just to check whether an autogenerated file had been manually edited. We decided it was easier to do what they wanted than argue with them, so we replaced it with CRC32C. That would have been faster than MD5, but nobody cares about saving a few milliseconds off reading a configuration file at st…

You don’t actually need to listen to auditors. People like you (who can’t be bothered to argue because it’s apparently too hard) is the reason that smartass is still selling their services.

You don’t actually need to listen to auditors.

At my company, that's a one-way ticket to the unemployment line.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#327
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

A company I know insists on rotating passwords fairly often. Everybody just increases the number at the end of their favourite password, i. e. intel1255

I use the month and year instead

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#328
post #41

Fingers crossed that this will enable some smart person to completely disable the management engine.

AFAIK the ME is required to initialize the processor so it can never be completely disabled. The best you could do is remove any code beyond necessary initialization which has mostly already been done by me_cleaner.

Afaik that stil leaves Computrace backdoor in the bios.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#329
post #14

Someone have a mirror? Seems the actual files are here: https://t.me/exconfidential/590 Edit: files are here https://mega.nz/folder/CV91XLBZ#CPSDW-8EWetV7hGhgGd8GQ or magnet:?xt=urn:btih:38f947ceadf06e6d3ffc2b37b807d7ef80b57f21

I'd assume spreading this is not legal?

spreading this is copyright infringement. Intel has to sue you for copyright infringement in court.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#330
post #10

Earlier quoted context omitted.

The shared stupid passwords like this that I've seen/had to use in my career would utterly shock you. Like hunter2 levels of shock.

> Like ******* levels of shock. What do you mean with 7 star levels?

This joke never gets old
Post reply on HN