News Massive 20GB Intel IP Data Breach Floods the Internet, Mentions Backdoors

Page 2 - Seeking answers? Join the Tom's Hardware community: where nearly two million members share solutions and discuss the latest tech.
Aug 7, 2020
1
0
10
This is what happens when you only host your own design data in-house - then you have underpaid contractors protecting that IP data!
 
I worked for Intel a bit ago and had the infosec working for me. They absolutely didn't anonymously steal this. And I have a fun bit of news for the person who violated their NDA. Everything is watermarked with who downloaded it and when. Hope they have LOTS of time and money.
Not necessarily. It very well could have been that a computer with access to the data got hacked at the partner company. Things like hardware keys and login credentials will only go so far to protect data if it is mirrored elsewhere on the company's network, or if one steals another's credentials. It likely wouldn't be hard to track down whose account was used to access the data, but that doesn't mean that person was the one who leaked it. I kind of doubt someone would leak this using their own credentials. Someone might get in trouble for not securing the data properly, but whoever leaked it won't necessarily get caught.

Also, if a user downloaded tens of gigabytes of confidential data directly from Intel over a short period of time, then it could be argued that its a lapse in Intel's own security. It would seem a bit suspicious if an account were downloading all that data at once, so if that was what happened, Intel should have cut them off and requested more information about what they needed it for. Again though, this might have just been data downloaded over the course of some years and stored on the company's network with minimal protection.
 
Aug 8, 2020
2
1
15
This just sounds like they accessed a bunch of the documents they do for customers. So you'll get a lot of technical details but nothing on their financials or process technology. The way it worked until a little while back (I used to have a RSNDA, but not currently) is they had:

CNDA (Corporate NDA, the easy one to get) -
Documents have Yellow covers, they'll give a lot of this stuff to tech websites (not the technical documents on chips, but stuff on upcoming designs).

RSNDA (Restricted-Secret NDA) -
Harder to get, documents come in Orangy-Yellow covers that can be hard to tell apart from the Yellow ones if one isn't around (!!??!!).
Can have info on new stuff that never becomes real. Also very early documentation (although before you get to datasheet version 0.7 or so it's really being brave using it to design anything). Also code-names that won't be anywhere on the Internet (although never Googled any of them, as thought it would be a data leak if Google knew what I did for a living).

Then the Internal Intel Secret stuff that has a Red cover and isn't supposed to leave their premises. You wouldn't find it on a customer-facing server or customer site. I only ever had one of those, from a pragmatic senior guy at Intel who realised my design was stuck without it. I suspect that doesn't happen any more. (I did send it back.)

P.S. They also have Spec updates at all levels (you might call them errata), so possibly one they tell the public about, a CNDA one with more info, an RSNDA one with even more stuff and an Intel-only one that may have even more in (you really have to find the problem yourself then ask).
 
  • Like
Reactions: SamirD
Aug 8, 2020
2
1
15
It sounds like they got the collection of NDA documents an Intel customer had, either by hacking them or someone leaking them. So would be design stuff and no secret Intel internal stuff (as they don't give non-design stuff out, unsurprisingly).
 

mchldpy

Distinguished
Jan 16, 2010
145
9
18,695
Somebody said one of you guys was really Richard Gere, star of an Officer, a Gerbil and a piece of plastic pipe.
I guess somebody or a family member got badly bruised from all the mean talk. Do you guys kiss your bruised mothers with those mouths?
 
D

Deleted member 14196

Guest
Somebody said one of you guys was really Richard Gere, star of an Officer, a Gerbil and a piece of plastic pipe.
I guess somebody or a family member got badly bruised from all the mean talk. Do you guys kiss your bruised mothers with those mouths?
What?