Lapsus$ hackers leak 37GB of Microsoft's alleged source code
bleepingcomputer.com
bleepingcomputer.com
(This leak doesn't interest me at all, but if ever the source for QBasic leaked, say.. well I might like to read it without becoming a wanted fugitive ;-))
You have to actually show damages, and nobody is going to care about personal research into obsolete software.
However, most games and software come with some form of DRM which you need to bypass to pirate them, and that's often banned explicitly in copyright legislation. It is under the American DMCA laws and, as far as I know, under European copyright laws, but your mileage may vary.
But yes, as far as I can tell, if someone shares their Good Old Games setup files with you and you download them, you're not breaking the law (though the person sharing the content obviously is).
Regardless of actual legality, you can still expect a lawsuit if your company pirates software and defending against that usually costs more than actually buying the software.
See e.g. https://scholarship.law.edu/cgi/viewcontent.cgi?article=1602...
thoughts on that? It seems that enforcing this against a downloader would require every single piece of media have an explicit limited license for downloading, which isn't practical right now
But again, I don't know the specifics of copyright law where you live. Perhaps your jurisdiction considers the person accepting the offer of an illegal copy to be a criminal as well.
If such a suit were to happen, the argument would probably boil down to where the infringement actually occurred. Does the server infringe when it sends copyrighted material (because that's where the copy is made), or does the client infringe when it requests said material (because they asked for an infringing copy)? Courts might accept both arguments and just decide everyone is liable.
Also all of that is for copyright, which (usually) covers published works. Trade secrets, which cover things not ever intended to be published, would just call both sides guilty of "misappropriating" the trade secret.
QBasic? - Why that modern thing. Just use the proper BASIC: https://github.com/microsoft/GW-BASIC ;)
Of course, the flip side of that is that anyone who has ever touched the leak is persona non grata in that industry. So if you're interested in learning how QBasic works, and you ever want to touch anything that interprets scripting code, don't touch those leaks.
FWIW disassembling QBasic (instead of obtaining leaked source) would be an absolute defense against a trade secret claim, but in terms of copyright you now have "access", and need to avoid "substantial similarity" in any source code you write. You aren't strictly-speaking "tainted" (clean-room is not a legal requirement), but if someone actually sued you for copying QBasic you'd better have a good legal argument for why every line of your code does not infringe upon the code you disassembled.
Not to take away from your useful points, but that would be quite the case in 2022! :-)
First, I want to be able to contribute code to open source projects, and I feel like seeing some "leaked" code could somehow taint me in a way that makes this more tricky for me.
Second, my employer expects me to act in a manner that reflects positively upon them. I don't think it's fair business dealings to read stolen code from someone who might be a competitor.
ReactOS audited their code and showed that none of it was Microsoft's.
And yet, both WINE and ReactOS have refused to use the leaks; ReactOS doesn't even allow people who have worked legitimately at MS in the past to be developers, simply because even the smell of contamination would expose the projects to enormous legal risks.
The only way I could imagine these leaks being useful is by "parallel construction" aka by comparing the source code with actual Windows binaries and then the WINE/ReactOS code to spot out differences to check, and then have a second person investigate the differences with only the note "check function XYZ with implementation in current Windows binary". But that's a lot of effort for very low reward, not to mention you'd need at least two very skilled experts and the low-hanging fruits having been picked already long ago.
[1] https://borncity.com/win/2020/10/01/entwickler-compiliert-wi...
[0] https://www.theverge.com/2022/2/21/22944335/us-copyright-off...
git reset --hard windows2000-sp4
/s(Actually I don't care anymore. Modern linux beats any version of windows in all my use cases)
It's the other way around for me. Windows Subsystem for Linux ftw.
I have used Linux as the primary Desktop OS for most of my life but I hope I will never have to go back ever again.
Are you aware that hackers have been leaking the source code of Linux for years?
Just think about that. There was a time where you'd not use an older version of an OS, but an older patch level of an OS and it didn't feel particularly wrong.
Unless you had a network of these, like a school, and a couple enterprising pranksters with Metasploit.
Cool. Having the only Itanium powered oven/fridge/washer gives him insane nerd street cred.
Time to really lock things down folks.
If you use a Google alternative, there's a good chance it's just Bing under the hood. So this leak could be a pretty big deal.
The problem is those companies are defunct, so their source repositories may not even exist anymore, let alone be online, e.g.:
http://www.chrisfenton.com/homebrew-cray-1a/
> After searching the internet exhaustively, I contacted the Computer History Musuem and they didn’t have any either. They also informed me that apparently SGI destroyed Cray’s old software archives before spinning them off again in the late 90’s.
I know at my employer, there's always pressure to half-ass things that aren't directly connected to some mechanism for making money. We recently migrated our company intranet site from one vendor to another, and the team that was running that project it as a "feature" that they would help us "clean up" by not assisting us migrating anything older than one year. Similarly, source control migrations (of which we've done several) often drop history, since it's usually way easier just to download the latest version and check it into the new system than figure out how to migrate the metadata. IIRC, Microsoft's TFS-VC to git migration tool will only migrate something like 180 days of history.
I hope you're not referring to my comment here [1]. Please note, that was, and remains, purely a speculation/hypothesis; see the thread after that. I have no knowledge, firsthand or otherwise, of them exploiting people's build systems.
Sus !
Second, zero trust is a very specific concept that basically refers to not trusting networks traditionally considered as more secure, such as corporate LANs. It is definitely not a panacea, not to mention that no large company, including Google, is able to implement it in full without incurring enormous costs.
Third, whatever you do, it's extremely difficult to protect against an inside job. I'm not suggesting it was a case at all, I'm just saying it's better not to jump to conclusions too hastily.
- based on the perenial patch Tuesday issues I am surprised it did not happen sooner.
- zero trust is a journey. we should accept that networks cannot be secure and instead look to implement principles of ZT away from the network. I like the open source OpenZiti project as a way to put strong identity and zt principles into our apps. Its not a panacea but it does make access and exploit much harder.
- correct, though if using attribute-based access controls we can at least massively limit what an insider could get access to... 37GB of source code across multiple different project at first blush looks like more than what 1 single user should have access to.
I work in the cyber insurance industry. This is not true.
Really? I mean our small company has never had our codebase breached and released by hackers, while Microsoft and their subsidiaries have had this happen several times. Similarly Twitch, Github, Valve... all have suffered source code breaches similar to the article.
None of the small companies I have ever worked for have had this issue, so it does seem that large tech companies have a higher probability of having their codebase successfully leaked.
We are also talking about Microsoft, which is probably amongst the top companies that are targeted the most by hackers across the world (mainly because of the impact when they are breached, rather than the ease of breach).
I assume when OP talks about the likelihood of a successful breach, they don't mean the success % of a breach, they mean the total number of successful breaches. When I worked at a big company the security team seemed to be putting out small fires all the time with targeted phishing attacks and so many laptops that could have missed an update, virtual machines getting ransomware e.t.c., and now I work for a smaller company and look after their IT as part of my role we have only had 1-2 fairly small issues across the last year.
I may just be line noise, but compiles and runs just as well.
I think Bing and Cortana will have some "algorithms" that might be worth a lot more for the right buyer. I mean Google's search algorithm is one of the best kept secrets in the industry.
https://www.microsoft.com/en-us/sharedsource/enterprise-sour...
And, IIRC, infamously the Chinese government too, because they made it a pre-condition of them purchasing Microsoft licenses that they must have source code visibility.
Even the communist party in China is more up to date then my own government
Well, there is for sure a lot to criticize about the CN government, but this precondition seems to me very natural (the OS is a very natural place for possible backdoors, otherwise...)
It does have other orgs in the screenshot, but all the leaks seem to be ASG related.
Like, what's the exit strategy there? They use your credentials, leak stuff, and you take the fall?