Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

391–400 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#391

Earlier quoted context omitted.

Internal sites? Set up your own CA infrastructure.

I rather spend my limited time working on other security issues.

Or (gasp) shippable features.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#392
post #281

Earlier quoted context omitted.

A company I know insists on rotating passwords fairly often. Everybody just increases the number at the end of their favourite password, i. e. intel1255

I once worked at a place that required passwords to be changed every month and contain at least one upper and lower case letter, digit, and punctuation, and not match any previous password. So the password for August, 2020 would be “August, 2020”.

This is super common, to the point where Microsoft used a similar password scheme as an example when talking about password spraying attacks at an RSA conference presentation

https://www.zdnet.com/article/microsoft-99-9-of-compromised-...

It's why I'm advocating within my organisation to get rid of password expiration and enforce 2FA for clients, but there's a lot of inertia to push against with some of them. At least uptake of 2FA is consistently increasing.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#393

Earlier quoted context omitted.

Imagine the reaction if the same thing was coming from China. Nobody would ask the question.

Nationality has nothing to do with it. I also don't trust Americans with such devices.

I'm talking about the general sentiment. You can see this on every* site, HN included. The litmus paper is that even pointing out something objectively true will get criticism (downvotes) rather than critical thinking. In the current atmosphere nobody asks the question when it comes to China/Russia/NK/Iran but will when it comes to the US despite the known history of hacking/spying on everyone else.

*Recently a reputable tech site wrote an article introducing DJI (ostensibly a company needing no introduction) as "Chinese-made drone app in Google Play spooks security researchers". One day later the same author wrote an article "Hackers actively exploit high-severity networking vulnerabilities" when referring to Cisco and F5. The difference in approach is quite staggering especially considering that Cisco is known to have been involved, even unwittingly, in the NSA exploits leaked in the past.

This highlights the sentiment mentioned above: people ask the question only when they feel comfortable that the answer reinforces their opinion.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#394

This kid has been posting these for fame (it's the same guy that posted the Daimler leak). I guess it's all fun and games until he finds himself in prison

That is indeed often the case with young narcissists (I don't know if it applies to this person, don't know him/her). That said, I remember the shocking arrogance and total disregard (for anything but their own ego) of a few young privileged "hackers", who were involved in DDOS services for hire, and also for some very nasty IoT bot net (if I recall correctly). Krebs wrote about them quite a bit. I think they even go…

IDK if wanting a bit of fame and validation makes you a narcissist per-say.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#395
post #389

Earlier quoted context omitted.

Interesting that it depends so much on region. Here in the UK, Sky offer a cheap 'over-the-top' streaming alternative to their satellite offerings, [0] so you could watch Game of Thrones for £8/month, provided you didn't mind the inferior video quality. [0] https://en.wikipedia.org/wiki/Now_TV_(Sky)

They have a "topup" now which allows you to get real, full-fat 1080p. Woohoo! I did actually add that to my subscription, and during lockdown have used it to re-watch Game of Thrones :)

I gave that a go but wasn't impressed by the 1080P quality. I suspect they're using a low bitrate.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#396
post #280
post #226

Earlier quoted context omitted.

You either have way more grit at arguing than most people or you haven't worked at a large and cumbersome organization. I know most people at those kinds of organizations just don't have the grit to fight every one of those battles all over again, and choose to do the things they can affect with reasonable effort instead. I'm not saying that grit would be a bad thing to have. I appreciate the people who do it. But yo…

I agree with your sentiment in general, but this is telling a dumbass where to go. Its not a hard argument to win. Md5 here is fine, its not a security check.

As a technical choice, that's true. So the argument shouldn't be hard to win, assuming you're dealing with reasonable people, who are also answering to reasonable people. Those people (e.g. the leadership) also need to care enough about that detail to just not dismiss your argument because making the change is not a problem for them. And they need to not be so security-oriented (in a naive way) as to consider a "safer" choice always a better one regardless of whether there's a reasonable argument for it or not.

That's more assumptions than it is sometimes reasonable to make.

"You don’t actually need to listen to auditors" is decidedly not true for a lot of people in a lot of situations, and arguing even for technically valid or reasonable things is an endurance sport in some organizations.

I mean, I even kind of want to agree with heavenlyblue's argument that you should fight that fight for the exact reason they're saying, and can see myself arguing the same thing years ago, but at least in case of some organizations, blaming people for taking skissane's stance would be disproportionate.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#397
With stuff like this being exfiltraded (let’s admit if hackers got this they prob could have a whole ton of fab secrets) it won’t be long until America’s IP is all in the hands of China/Russia/Europe.

We will have confirmation when China launch a ‘Xi Lake’ x86 compatible cpu...

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#398

Earlier quoted context omitted.

Once I got a complaint from a security auditor that some code was using MD5. It wasn’t being used for any security purpose, just to check whether an autogenerated file had been manually edited. We decided it was easier to do what they wanted than argue with them, so we replaced it with CRC32C. That would have been faster than MD5, but nobody cares about saving a few milliseconds off reading a configuration file at st…

You don’t actually need to listen to auditors. People like you (who can’t be bothered to argue because it’s apparently too hard) is the reason that smartass is still selling their services.

I was on the receiving end of a security audit issue. I closed the bug s won't fix, my lead approved it, but when the team who paid the security auditor found out they demanded I fix it. I had to argue with it, infosec, and the auditor. Nobody really cares what I did, they just wanted to follow the rules. After a month of weekly hour long meetings I relented and changed the code.

You're often not arguing with the auditor, you're arguing with the person who paid the security auditor in the first place who is likely not even technical. That's a battle toy will likely never win.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#399
post #282

Earlier quoted context omitted.

Reminds me a little of a place I worked. They sold very expensive devices that were actually an off-the-shelf 1U PC with custom software (which provided the real value). The problem — and this dates it — was that the PCs had a game port¹, which gave away that this custom hardware was really just a regular consumer PC. So they had some fancy plastic panels made to clip on the front and hide the game port. ¹ https://en…

I remember early in my career I came across a Unisys “mainframe”, which was literally a Dell box with a custom bezel, clustered with a few other nodes with a Netgear switch.

Many non-IBM mainframe vendors switched to software emulation on more mainstream platforms-nowadays mainly Linux or Windows on x86, but in the past SPARC and Itanium were also common choices. What you saw may have been an instance of that. A software emulator can often run legacy mainframe applications much faster than the hardware they were originally written for did.

(With Unisys specifically, at one point they still made physical CPUs for high end models, but low end models were software emulation on x86; I’m not sure what they are doing right now.)

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#400

Earlier quoted context omitted.

Here is the real thing: are you confident enough in your statement to argue that way when confronted by your government (or whatever is the concerned body here)? If yes, then feel free to do whatever you want with your free time and bandwidth, but otherwise you're better to stay as far as possible from these data.

well in any case thanks for FUDge-packing this discussion and sharing your opinion which is based on nothing. i'll make sure to credit you as my partner-in-crime after I get my door kicked in for downloading files on the internet.

I notice that you have no one in your circle of acquaintances who has illegally downloaded movies about torrents and got caught. I don't know how it is in other countries, but here in Germany friendly people ring your doorbell and take everything that is connected to electricity :). And if there is any data in there that is very damaging to Intel, then I think they will take the trouble to look for these people (at least in certain countries)
Post reply on HN