Live data from Hacker News

20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

twitter.com

461–470 of 476 posts

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#461
post #456

Earlier quoted context omitted.

I wrote this poorly. Meant whomever left this data in the clear is guilty of something and or liable.

It would be like keeping a dropped wallet - the person who keeps it is guilty, not the person who accidentally dropped it.

No it wouldn't. It would be like taking a picture of a dropped wallet on the street.

Regardless, under what moral framework are we operating such that obvious guilt is prescribed to anyone who might pick up a wallet in the street, anyway? Of what crime are they guilty?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#462

Earlier quoted context omitted.

I have a feeling that these auditor people just make up bullshit when they can't find something real. The last few we have got have come up with total non issues marked as severe because they are easy to "exploit". Meanwhile I have been finding and fixing real security issues regularly. To be fair it would be extremely difficult for an external person to find issues in the limited time they have so the audit comes do…

Some years ago I worked in $BIGBANK and auditor from $GOVERMENT told as to change street name property from textfield to dropdown (for all countries) to help them with fraud detection, and remove all diacritic characters from client names their new software don't like them. I told my manager that they are idiots and I won't listen them, he was like 'OK, as I expected' never done anything about it, next auditors didn'…

This makes me wonder about the reliability of address verification technology.

There are plenty of addresses where the official version in databases is slightly off from what people actually write on their mail. If I got a credit card transaction with the "official" version, that would be a significant fraud signal, that they were sourcing bogus data from somewhere.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#463
post #438

Earlier quoted context omitted.

What is this weird incessant need to play devils advocate. Sometimes people are just right.

Because most times people aren't "just right", they're just unwilling to widen their point of view, and/or they turn the issue into a way to assert their own importance and intellect over someone else at the expense of those they work with. I don't need some coworker getting into some drawn out battle about how MD5 is fine to use when we can just use SHA (or CRC32C as that person did, which is more obviously non-usef…

> they turn the issue into a way to assert their own importance and intellect over someone else at the expense of those they work with.

This is exactly what the auditor is doing.

How can you not see the irony here?

> I don't need some coworker getting into some drawn out battle

This isn't a drawn out battle. This is a really fast one, md5 is fine here, you didn't check the context of its use, thats fine, whats the next item on your list?

Whats fucking hard about that?

Is this some kind of weird cultural thing with American schooling teaching kids they can't question authority?

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#464
post #463

Earlier quoted context omitted.

Because most times people aren't "just right", they're just unwilling to widen their point of view, and/or they turn the issue into a way to assert their own importance and intellect over someone else at the expense of those they work with. I don't need some coworker getting into some drawn out battle about how MD5 is fine to use when we can just use SHA (or CRC32C as that person did, which is more obviously non-usef…

> they turn the issue into a way to assert their own importance and intellect over someone else at the expense of those they work with. This is exactly what the auditor is doing. How can you not see the irony here? > I don't need some coworker getting into some drawn out battle This isn't a drawn out battle. This is a really fast one, md5 is fine here, you didn't check the context of its use, thats fine, whats the ne…

> This is exactly what the auditor is doing.

The auditor was asked to do it and is being paid to do it. Presumably, the people arguing are paid to implement the will of those that pay them. At some point people need to stop arguing and do what they're paid to do or quit. Doing this over wanting to use MD5 seems a pretty poor choice of a hill to die on.

> This is a really fast one, md5 is fine here, you didn't check the context of its use, thats fine, whats the next item on your list?

There are items like this all throughout life. Sure, you can be trusted to drive above the speed limit on this road, and maybe the speed limit is set a little low. But we have laws for a reason, and at some point you letting the officials know that the speed is two low and they really don't need to make it that low goes from helpful to annoying everyone around you.

> Whats fucking hard about that?

Indeed, what is so hard about just accepting that while you're technically correct that MD5 isn't a problem, you're making yourself a problem when you fight stupid battles nobody but you cares about, but everyone has to deal with?

> Is this some kind of weird cultural thing with American schooling teaching kids they can't question authority?

Hardly. Pompous blowhards exist in every culture. Also, that's hilarious. Your talking about a culture that rebels against authority just because they think they that's what they're supposed to do, even if it's for stupid reasons and makes no sense. See the tens of millions of us that refuse to wear masks because it "infringes on our freedom".

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#465
post #226

Earlier quoted context omitted.

You don’t actually need to listen to auditors. People like you (who can’t be bothered to argue because it’s apparently too hard) is the reason that smartass is still selling their services.

You either have way more grit at arguing than most people or you haven't worked at a large and cumbersome organization. I know most people at those kinds of organizations just don't have the grit to fight every one of those battles all over again, and choose to do the things they can affect with reasonable effort instead. I'm not saying that grit would be a bad thing to have. I appreciate the people who do it. But yo…

I do it for the sake of educating our management.

For now 10 years, I refuse to acknowledge the finding of the consulting company which flags the password scheme I use (passphrases) because the norm they use (a national one) talks about czps, symbols etc.

I refuse to sign off and note that our company is a scientific one and to the difference of the auditors, we understand math taught to 16 yo children.

This goes to the board who gets back to me, I still refuse on ethical gtounds and we finally pass.

This is sad that some auditors are stupid when some other are fantastic and that you depend on which one you get assigned.

A good read: https://serverfault.com/q/293217/78319

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#466

Earlier quoted context omitted.

>Which country laws does apply? At the very least, Intel owns the copyright on this material, so sharing it is a copyright violation in any country that is a signatory to the Berne Convention or the TRIPS Agreement, which is effectively almost the entire planet. Then you have to add Trade Secret laws on top of that, which will have slightly narrower jurisdiction but still impact a lot of countries. There are very few…

Hi msbarnett: sorry unrelated to this thread. In an older thread you mention an acronym TFA. The thread was a discussion on sparse files and removing bytes from the front of a file. What is TFA?

If you’re referring to: https://news.ycombinator.com/item?id=20110301, it stands for “The Fucking Article” as in http://www.catb.org/jargon/html/R/RTFM.html

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#467

Earlier quoted context omitted.

Hi msbarnett: sorry unrelated to this thread. In an older thread you mention an acronym TFA. The thread was a discussion on sparse files and removing bytes from the front of a file. What is TFA?

If you’re referring to: https://news.ycombinator.com/item?id=20110301 , it stands for “The Fucking Article” as in http://www.catb.org/jargon/html/R/RTFM.html

Haha - thanks :-) I thought it was an abbreviation for some special tome on Operating Systems design.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#468

Earlier quoted context omitted.

That is indeed often the case with young narcissists (I don't know if it applies to this person, don't know him/her). That said, I remember the shocking arrogance and total disregard (for anything but their own ego) of a few young privileged "hackers", who were involved in DDOS services for hire, and also for some very nasty IoT bot net (if I recall correctly). Krebs wrote about them quite a bit. I think they even go…

IDK if wanting a bit of fame and validation makes you a narcissist per-say.

Not per-se, indeed. But if that urge for validation is for something that's fundamentally wrong and/or only supports an person's failure to critically assess their own actions, then it usually is narcissism.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#469

Earlier quoted context omitted.

I've heard it put this way: If you force users to trade convenience for security, they will find a way to obtain convenience at the expense of security.

It's true, and often it's not laziness - corporate security measures are often focused only on denying access, and they're so overbearing that, were they followed to the letter, they could easily shut the company down. It's through workarounds that actual work gets done.

I remember having issues with a corporate email system where base64/uuencoded data would fail to get through with a very rough dependency on size - large files had a smaller chance of getting through but it was clear that there wasn't a hard size limit. Eventually someone twigged that the problem was a "rude word" scanner, and that beyond a certain size you would hit the "scunthorpe" problem, and forbidden words would appear in the ASCII text randomly.

Re: 20GB leak of Intel data: whole Git repositories, dev tools, backdoor mentions

#470
post #463

Earlier quoted context omitted.

> they turn the issue into a way to assert their own importance and intellect over someone else at the expense of those they work with. This is exactly what the auditor is doing. How can you not see the irony here? > I don't need some coworker getting into some drawn out battle This isn't a drawn out battle. This is a really fast one, md5 is fine here, you didn't check the context of its use, thats fine, whats the ne…

> This is exactly what the auditor is doing. The auditor was asked to do it and is being paid to do it. Presumably, the people arguing are paid to implement the will of those that pay them. At some point people need to stop arguing and do what they're paid to do or quit. Doing this over wanting to use MD5 seems a pretty poor choice of a hill to die on. > This is a really fast one, md5 is fine here, you didn't check t…

> do what they're paid to do or quit.

I'm paid to tell idiots where to go. My boss doesn't pay me 6 figures to toe the line and fill in boxes. She pays me to use my judgement to move the company forward. I'm not wasting my time and her money on this sort of garbage and if they can't see the difference between casual use and secure use them we need to rethink our relationship with this company or they need to send us someone new.

> Your talking about a culture that rebels against authority

You just used the line "do what you're told or quit".

The cognitive dissonance here is unreal.

Post reply on HN