1.原文连结:连结过长者请使用短网址。
https://reurl.cc/VjlNgn
2.原文标题:标题须完整写出(否则依板规删除并水桶)。
Hackers leak 190GB of alleged Samsung data, source code
3.原文来源(媒体/作者):例:苹果日报/王大明(若无署名作者则不须)
BleepingComputer / Ionut Ilascu
4.原文内容:请刊登完整全文(否则依板规删除并水桶)。
The Lapsus$ data extortion group leaked today a huge collection of
confidential data they claim to be from Samsung Electronics,
the South Korean giant consumer electronics company.
机翻:
Lapsus$ 资料勒索组织今天泄露了他们声称来自韩国消费电子巨头
三星电子的大量机密资料。
The leak comes less than a week after Lapsus$ released a 20GB document
archive from 1TB of data stolen from Nvidia GPU designer.
机翻:
在 Lapsus$ 从 Nvidia GPU 设计者窃取的 1TB 资料中发布 20GB
文档档案后不到一周,泄漏就发生了。
Gang teases Samsung data leak
机翻:
勒索组织取笑三星资料泄露
In a note posted earlier today, the extortion gang teased about
releasing Samsung data with a snapshot of C/C++ directives in Samsung
software.
机翻:
在今天早些时候发布的一份说明中,勒索组织取笑了有关发布三星资料
以及三星软件中 C/C++ 指令快照的内容。
Shortly after teasing their followers, Lapsus$ published a description of the
upcoming leak, saying that it contains “confidential Samsung source code”
originating from a breach.
机翻:
在取笑他们的追随者后不久,Lapsus$ 发布了对即将发生的泄密事件的描述,
称其中包含源自泄露的“机密三星原始码”。
- source code for every Trusted Applet (TA) installed in Samsung’s TrustZone
environment used for sensitive operations (e.g. hardware cryptography, binary
encryption, access control)
机翻:
三星 TrustZone 环境中安装的每个受信任小应用程式 (TA) 的原始码,
用于敏感操作(例如硬件加密、二进制加密、存取控制)
- algorithms for all biometric unlock operations
机翻:
所有生物特征解锁操作的算法
- bootloader source code for all recent Samsung devices
机翻:
所有最新三星装置的引导程式原始码
- confidential source code from Qualcomm
机翻:
来自高通的机密原始码
source code for Samsung’s activation servers
机翻:
三星授权服务器的原始码
- full source code for technology used for authorizing and authenticating
Samsung accounts, including APIs and services
机翻:
用于授权和验证三星帐号的技术的完整原始码,包括 API 和服务
If the details above are accurate, Samsung has suffered a major data breach
that could cause huge damage to the company.
机翻:
如果上述详细信息准确无误,则三星已遭受重大数据泄露,
可能对公司造成巨大损害。
Lapsus$ split the leaked data in three compressed files that add to almost
190GB and made them available in a torrent that appears to be highly popular,
with more than 400 peers sharing the content. The extortion group also said
that it would deploy more servers to increase the download speed.
机翻:
Lapsus$ 将泄露的数据拆分为三个压缩档,这些文件增加了近 190GB,
并使它们可用的 torrent 形式,似乎非常受欢迎,有 400 多个使用者群共享内容。
勒索组织还表示,将部署更多服务器以提高下载速度。
Included in the torrent is also a brief description for the content available
in each of the three archives:
机翻:
torrent 中还包含对三个档案中每个档案中可用内容的简要说明:
- Part 1 contains a dump of source code and related data about
Security/Defense/Knox/Bootloader/TrustedApps and various other items
机翻:
第 1 部分包含有关 Security/Defense/Knox/Bootloader/TrustedApps 和其他各种项目
的原始码和相关资料的转储
- Part 2 contains a dump of source code and related data about device security
and encryption
机翻:
第 2 部分包含有关装置安全和加密的原始码和相关资料的转储
- Part 3 contains various repositories from Samsung Github: mobile defense
engineering, Samsung account backend, Samsung pass backend/frontend, and SES
(Bixby, Smartthings, store)
机翻:
第 3 部分包含来自三星 Github 的各种储存库:行动(装置)防护工程、三星帐号后端、
三星通行证后端/前端和 SES(Bixby、Smartthings、商店)
It is unclear if Lapsus$ contacted Samsung for a ransom, as they claimed in
the case of Nvidia.
机翻:
目前尚不清楚 Lapsus$ 是否联系三星索要赎金,
正如他们在 Nvidia 案中所声称的那样。
BleepingComputer has contacted Samsung for a statement about the Lapsus$ data
leak and will update the article when the company replies.
机翻:
BleepingComputer 已联系三星就 Lapsus$ 资料泄露发表声明,
并将在公司回复时更新文章。
This is developing story
机翻:
这是发展中的故事
5.心得/评论:内容须超过繁体中文30字(不含标点符号)。
──────────────────────────────────────
Lapsus$ 真的有够扯,前几天才跟 Nvidia 杠上,
拿走 Nvidia 1TB 的资料,而且对外销售 1 百万美金 N 的 driver src
而且要求 N 要开源 GPU driver。
之前看到有一则讯息勒索组织说有一个人向它买了,
不过讯息貌似消失了
现在换三星中奖,
如果照他们说的话,没有夸大不实的话
三星的资安真的GG了