Is releasing this legal? It seems like this person isn't really disguising their identity or concerned about breaking the law. In their profile they even seem to brag about leaking company's code.
Of course it's not legal. This is exfiltrated intellectual property being shared without license.
20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
151–160 of 476 posts
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#152Fingers crossed that this will enable some smart person to completely disable the management engine.
AFAIK the ME is required to initialize the processor so it can never be completely disabled. The best you could do is remove any code beyond necessary initialization which has mostly already been done by me_cleaner.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#153This is more embarrassing than harmful. Having worked at companies like intel, it's not really that damaging leaking some of this IP - the worst that happens is some open source project gets slightly better or you have a few more bugs (not that Intel are lacking in that area). The second we see internal marketing, pricing & road map slides- that's when you know they're in real trouble.
- copyright infringement
- patent infringement
- actual backdoors (the word backdoor does appear but there are many ways how it can already without they being a backdoor got spying including bad naming sense of engineers and code used during prototyping only
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#154Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#155The advice to try a password of “Intel123” on any protected files says it all. This organisation genuinely deserves whatever is coming for them.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#156Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#157Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#158Earlier quoted context omitted.
... They're claiming it came from an NDA'd source of IP that's shared with customers. Given that it _appears_ like there are backdoors in this Firmware code, we can conclude that if there are such backdoors then they were shared with numerous customers. That really doesn't improve the optics of the breach.
Alternately, as others have noted, it could be overloaded nomenclature and doesn't actually indicate a backdoor. Which would be an excellent reason for them to feel comfortable sharing said 'backdoors' with their customers.
Or maybe some well documented Intel management features need to backdoor there own security mechanisms to work.
Or ...
Well the point is it's a starting point for someone dissecting the data but not much more.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#159Earlier quoted context omitted.
Usually this. Or in my workplace, an image. Antivirus are some crazy shit that may trigger on any random action and will teach people to follow the most unsafe procedures without questioning, so they can get anything done.
I've heard it put this way: If you force users to trade convenience for security, they will find a way to obtain convenience at the expense of security.
This has been brought up a million times in the context of DRM, but it is true in the general case as well.
Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions
#160Earlier quoted context omitted.
Because until this thing gets diffused and dissected by everyone and their mothers, the law is likely to view it as publication of confidential trade secrets, and people who can be confirmed to be spreading such things can get federal time, e.g. [1] for example. Using a VPN is the barest of mechanisms to try to obscure your identity to avoid this sort of punishment. [1] https://www.wsj.com/articles/SB1000142405297020…
Right but if you just download without seeding, no crime is being committed, yes? So seems like the barest you can do is "disable seeding", not "use a VPN".
“Misappropriation” means:
(i) acquisition of a trade secret of another by a person who knows or has
reason to know that the trade secret was acquired by improper means; or
(ii) disclosure or use of a trade secret of another without express or
implied consent by a person who
(A) used improper means to acquire knowledge of the trade secret; or
(B) at the time of disclosure or use knew or had reason to know that
his knowledge of the trade secret was
(I) derived from or through a person who has utilized improper means
to acquire it;
(II) acquired under circumstances giving rise to a duty to maintain
its secrecy or limit its use; or
(III) derived from or through a person who owed a duty to the person
seeking relief to maintain its secrecy or limit its use; or
(C) before a material change of his position, knew or had reason to
know that it was a trade secret and that knowledge of it had been
acquired by accident or mistake.