Live data from Hacker News

Cybercriminals who breached Nvidia issue one of the most unusual demands ever

arstechnica.com

261–270 of 693 posts

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#261

Probably a stupid question, but even if the hackers release everything, wouldn't be illegal for competitors to use that information since NVIDIA most likely has already patented that?

I'd go a step further and say that any work on the open source Nouveau driver would instantly become a legal hell. When the proprietary code gets dumped illegally, you have to be extremely wary with new submissions to the project because one stolen method and nvidia's lawyers are all over you.

This is why leaked Windows source code is actually terrible for products like Proton and ReactOS.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#262
post #5

> So, NVIDIA, the choice is yours! Either: Officially make current and all future drivers for all cards open source, while keeping the Verilog and chipset trade secrets... well, secret OR Not make the drivers open source, making us release the entire silicon chip files so that everyone not only knows your driver's secrets, but also your most closely-guarded trade secrets for graphics and computer chipsets too! Intere…

No single piece of software has wasted more of my time than Nvidia's drivers, mostly (though not exclusively) on Linux. They've rendered my OS unbootable so many times over the years. So many times I've spent whole days of my life troubleshooting, upgrading, downgrading, configuring, rebooting. Then often reinstalling the OS after their installers mess stuff up in ways that are impossible to even know until they pop…

Haven't had an issue with the nvidia proprietary drivers since the 495 series, they've gotten a lot better recently, and more frequently updated, though still less configurable than their windows counterparts.

Currently on driver 510.54 and playing Elden Ring on maximum settings with a 2080 super without issue.

Though you do have to add a kernel parameter to use nvidia's DRM mode for best performance which is non-obvious. And hybrid GPU laptops are a whole other thing, I guess.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#264
post #115
post #73

Earlier quoted context omitted.

Oh, tell me about it. +Installs Linux, this time determined to make it daily driver. Why is this so slow though? - You need to install Nvidia drivers + Oh, OK makes sense. -- INSTALLS NVIDIA DRIVERS -- -- LINUX NO LONGER BOOTS, OBSCURE ERROR MESSAGE, FURIOUSLY GOOGLING ON A TINY PHONE SCREEN TRYING TO RESOLVE THE ISSUE -- Later made myself a Hackintosh, eventually bought an actual Mac. The Hackintosh stuff was much,…

Interesting. I’ve not used Linux as my mainly driver for years. I miss it and I want to come back but I basically don’t have any decent PC anymore so I have the freedom to get/build one. When I used it, ironically, NVidia was the way to go on Linux and ATI/AMD was a shit show. Is AMD ok nowadays ? My needs are mostly confortable casual gaming where I don’t care having more than 60fps and I don’t play online (so this…

I have built my desktop with top end components: ASRock X570M Pro4, ASUS ROG Radeon RX 6800, AMD Ryzen 7 5800X, WDBlack Nvme, and I have no issue at all with drivers or anything (I also use gentoo with a self-configured kernel, no genkernel). It's my daily driver for working and gaming 4k (with 3 4k monitors)

Linux has no issue with drivers and/or video cards in particular, people just need to pay some attention when buying components, saying that linux has issues with graphics because of nvidia it's a bit unfair, nouveau is not able to use acceleration because the videocard doesn't activate it if it isn't loaded by the official nvidia blob, so if linux is supposed to have issues with graphic card while vendors actively create obstacles, we will never figure the real issue and hold the right people accountable: It's nvidia that has still issues with linux

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#265

Earlier quoted context omitted.

It would be much easier if crypto could just die out.

It won't, and it's a very important technology since it's the only way for humans to store digital property without relying on some government or corporation. Also, it ever gets attacked, much more will be at stake, including your freedom for choosing what software can be run on your computer.

How on earth does it stop reliance on a government? Or specifically, prevent reliance on some entity monopolising force? This crypto wet dream, like all libertarian wet dreams, ultimately relies on there being a benevolent entity that prevents someone with a bigger gun than you from marching in and taking whatever they want.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#266
post #248
post #235

Earlier quoted context omitted.

> I'm not aware of any case law around whether private keys are copyrightable That's often up to debate, apparently. I think most recently, Widevine private keys regularly get DMCA'd.

Distributing the keys is illegal, but what about using they keys and distributing the resulting signed firmware?

Good point, but also good luck explaining that to a judge.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#267
post #5

> So, NVIDIA, the choice is yours! Either: Officially make current and all future drivers for all cards open source, while keeping the Verilog and chipset trade secrets... well, secret OR Not make the drivers open source, making us release the entire silicon chip files so that everyone not only knows your driver's secrets, but also your most closely-guarded trade secrets for graphics and computer chipsets too! Intere…

No single piece of software has wasted more of my time than Nvidia's drivers, mostly (though not exclusively) on Linux. They've rendered my OS unbootable so many times over the years. So many times I've spent whole days of my life troubleshooting, upgrading, downgrading, configuring, rebooting. Then often reinstalling the OS after their installers mess stuff up in ways that are impossible to even know until they pop…

Yeah. It directly led me to buying AMD hardware this time and I'm much happier for it. AMD aren't perfect but at least their drivers are in the kernel.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#268

I wonder how professional these criminals are. A crime syndicate would silently ask for money. This seems either a false flag operation for a group wanting something else, or much more likely a kid playing around and finding an unlocked door. That last case, a kid pissing of a powerfull entity with a crime, generally does not end well for the kid. I don't see NVidia publicly giving in and loosing face, so there seems…

So you think nVidia will want to see the release of all of its chip schematics? That's an interesting position, but I fail to see how that would be a good idea for them. Perhaps if they are hoping the hackers will be apprehended before Friday.

It's a standard rock vs hard place situation. But

1) why should nVidia trust the attackers? nVdia might give in, and the files might still be leaked. The attackers should be able to guarantee they won't release the files AND nobody steals the files from them. Hard sell for the attackers, especially with a kid profile .

2) These files are legally toxic. You can't look at them and then publicly act on their content. So anything a third party can do has to happen at arm's length, parallel construction style. This also goes for open source devs, who can't permit nouveau gettibg kicked out of the legal repositories.

3)It is well possible the leak is not as damaging as it looks. People in the industry swap jobs all the time, and take knowledge with them. People accidentally do small leaks all the time, being sloppy with data entrusted to them. It seems reasonable for other big organizations to already have some level of knowledge of the content.

On the other side of the coin is the fully legal loss of control of their software. They also open themselves up to future ransomers ('Danegeld').

I'm not saying high level people at nVidia aren't swearing loudly right now, but a 'let the chips fall as they may' response seems most likely to me, especially combined with a 'we'll very publicly sue the attackers in the ground, as an example for all wannabes' response.

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#269
post #5

> So, NVIDIA, the choice is yours! Either: Officially make current and all future drivers for all cards open source, while keeping the Verilog and chipset trade secrets... well, secret OR Not make the drivers open source, making us release the entire silicon chip files so that everyone not only knows your driver's secrets, but also your most closely-guarded trade secrets for graphics and computer chipsets too! Intere…

No single piece of software has wasted more of my time than Nvidia's drivers, mostly (though not exclusively) on Linux. They've rendered my OS unbootable so many times over the years. So many times I've spent whole days of my life troubleshooting, upgrading, downgrading, configuring, rebooting. Then often reinstalling the OS after their installers mess stuff up in ways that are impossible to even know until they pop…

> No single piece of software has wasted more of my time than Nvidia's drivers

I see you haven't used printers much :)

Re: Cybercriminals who breached Nvidia issue one of the most unusual demands ever

#270
post #208

There are two scenarios where carrying out their threat plausibly helps the open source community: 1) A source drop demonstrates that Nvidia incorporated GPLed code into their drivers. This is, honestly, unlikely - Nvidia has sufficiently competent lawyers to ensure that everyone they employ is extremely aware of what the consequences of that would be 2) The source drop includes the private keys used to sign Nvidia G…

> and whether it's a DMCA violation to make use of leaked keys if you don't violate any other technical protection mechanisms.

It might depend on jurisdiction. The devs could limit liability by not running without the user providing the secrets at build or runtime.

Post reply on HN