Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

111–120 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#111
post #80
post #76

Earlier quoted context omitted.

As in a manhole cover in a street for maintenance.

Yes, yes. Seems like an outdated term. Downvotes accepted.

> Seems like an outdated term. Downvotes accepted.

Manhole is, indeed, an outdated term. Generally the preferred term is "Maintenance Hole". Still abbreviated MH, and people in the field use all three interchangeably (much like metric/imperial).

Source: I work with storm/sanitary/electrical maintenance holes.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#112
post #11

At a previous workplace we had a few places in the code which used the word backdoor. It was not an actual backdoor though, but merely a debugging server that could be enabled and allowed you to inspect internal state during runtime. At some point I removed the word backdoor, fearing it would get to a customer or during an audit someone would misunderstand. :|

Frankly I don't think Intel's track record affords them the privilege of having good faith be assumed with something like this.

Intel employes 100,000 people, and most of them aren't even aware of most of Intel's transgressions, let alone approve of them.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#114
post #2

> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel. Can't say I'm surprised, people are lazy. Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things…

I worked for a company that made servers. In the on board management system's source code I remember seeing "base64 encryption". I think they removed it by the time I left, but still.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#115
post #29

Intel denies it was hacked: https://twitter.com/TheRegister/status/1291461942624677889

It wasn't hacked... But these files came into the hands of an unauthorised user... That seems a lot think something of theirs got hacked...

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#116
post #101

Earlier quoted context omitted.

I can agree with that with the caveat that "enabled" has to be at either something that only the user can do. If it requires that the customer intentionally run a debug build, that's fine; if it can be toggled on without their knowledge, then it's a problem.

It was disabled by default, and could only be enabled using environment variables. Even when enabled, the whole thing ran in Docker and the socket was bound to loopback, so you could only connect to it from within the container. When the intention is a debugging server, making it exposed to the world is a mistake and a security vulnerability. At that point it is effectively a backdoor, but the difference between a hi…

That doesn't sound very safe.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#117
post #11

At a previous workplace we had a few places in the code which used the word backdoor. It was not an actual backdoor though, but merely a debugging server that could be enabled and allowed you to inspect internal state during runtime. At some point I removed the word backdoor, fearing it would get to a customer or during an audit someone would misunderstand. :|

A manufacturer wanted to upgrade one of their equipment lines to be more modern. The developers of the original product, both hardware and software, were no longer with the company. Since they just wanted to add some new features on top and present a better rack-based interface to the user, they decided to build a bigger box, put one of the old devices inside the box, then put a modern PC in there, and just link the…

This can't be real... are you serious? It sounds like one of those silly buisness parabels!

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#118
post #67

Earlier quoted context omitted.

Which country laws does apply? Is it really illegal to share this in the whole world? Im not so sure about that.

Intel is an American company; so wherever there is an extradition treaty with the USA and where there are also similar laws.

No country Will extradite their own citizens, though. If intel wants the person punished, they have to sue them in the country they live in.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#119
post #67

Earlier quoted context omitted.

Which country laws does apply? Is it really illegal to share this in the whole world? Im not so sure about that.

Intel is an American company; so wherever there is an extradition treaty with the USA and where there are also similar laws.

Wouldn't the publishing part just be standard copyright infrignement and just a civil matter?
Post reply on HN