Intel sues former staffer for allegedly stealing Xeon cloud secrets in USB drives and exploiting info at Microsoft
- Reference: 1612772530
- News link: https://www.theregister.co.uk/2021/02/08/intel_vs_varun_gupta/
- Source link:
In a [1]lawsuit [PDF] filed on Friday in a federal district court in Oregon, Intel said Dr Varun Gupta spent a decade at Chipzilla before departing in January 2020. The suit alleges that Gupta had a handle on Intel’s trade secrets and strategies for selling custom Xeon chips, among other confidential data, and was not afraid to exploit that information in his new gig at Microsoft.
[2]
“Gupta explicitly referred to pricing offers and technical specifications that Intel had developed and marketed for other cloud computing environments to leverage favorable terms for Microsoft,” the suit stated. In other words, the allegation is that Gupta used details of confidential deals Intel had struck with Microsoft's cloud rivals to negotiate better contracts for the Azure goliath.
The defendant had no right to use that information. Indeed, Intel said he would have been aware he was not allowed to because his employment contract contained lots of clauses about trade secrets, and he was asked to sign a “trade secret acknowledgment form” that “specifically identifies the categories of confidential information and trade secrets to which the departing employee has had access and confirms the employee’s contractual obligation not to use or disclose that information post-employment.”
[3]
But Intel alleged that in his last days at the company, Gupta moved 3,900 internal documents from his company laptop to two external USB-based drives, one made by Seagate and another from Western Digital. The suit claimed Intel knows the drives’ serial numbers.
Top engineer who stole trade secrets from Google's self-driving division pardoned on Trump's last day as president [4]READ MORE
Four days after leaving Intel, Gupta took up a new role as a principal of strategic planning in Microsoft’s Cloud and Artificial Intelligence department. The suit alleged he immediately used info he accessed at Intel “in head-to-head negotiations with Intel concerning customized product design and pricing for significant volumes of Xeon processors.”
Intel’s suit said that its own staff who subsequently negotiated with Gupta at Microsoft became suspicious he had stolen documents from Chipzilla. The chip giant’s investigations, we're told, yielded evidence about both external drives being used to store sensitive files, and Intel asked Gupta to hand over the first one. He said he could not find it, and had never connected it to an Intel-owned PC.
By this time Intel had asked Microsoft for help. The Windows giant, we're told, discovered the first drive had been used within its walls, including on Gupta’s Microsoft-issued PC.
The suit alleged that one of the files from the disk was also found on that Microsoft PC’s hard drive. Gupta said he gave away the second drive and does not know where it might be found. It has never been recovered. And the second drive is even scarier, because it contains documents including “highly sensitive product specifications for customized Xeon processors.”
“This confidential information would be extremely useful to Gupta in his employment at Microsoft because it provided him information about Intel’s manufacturing capacity and customized product offerings for other data centre and cloud computing environments—which Gupta could then leverage in his negotiations with Intel on behalf of Microsoft,” the suit alleged.
The filing stated that Gupta claimed he accessed the Intel documents either from public portals or was provided them by Microsoft. Intel assessed that argument as “nonsensical” based on its probe into the two external drives.
If nothing else, this tells us that Microsoft and Intel both have some impressive forensic capabilities.
Nutanix, VMware are fighting again – yet it's just a sideshow. Why? Look at the giant predators circling [5]READ MORE
Intel wants Gupta to hand over the drives and any devices to which they were connected, then sign documents declaring he has no more of the company’s information in his possession.
Chipzilla also wants $75,000, which it said is the cost of getting the matter to its current state, plus costs, compensation for breach of contract, and “an award of exemplary/punitive damages.”
[6]
Intel doesn’t say what that will add up to beyond the $75k costs it claims to have incurred so far. But the filing refers to the case of Anthony Levandowski, the top engineer who pleaded guilty to [7]stealing self-driving car trade secrets from Google. Levandowski was jailed and hit with a lawsuit seeking $179m in damages, then [8]pardoned by Donald Trump. ®
Get our [9]Tech Resources
[1] https://regmedia.co.uk/2021/02/08/intel_gupta_filing.pdf
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_datacentre/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCEZyjULQOhLZcO7Xkaj5gAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_datacentre/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCEZyjULQOhLZcO7Xkaj5gAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/01/20/levandowski_bannon_trump_pardons/
[5] https://www.theregister.com/2021/01/06/nutanix_vs_vmware_2021_edition/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_datacentre/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCEZyjULQOhLZcO7Xkaj5gAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2020/08/05/levandowski_prison_sentence/
[8] https://www.theregister.com/2021/01/20/levandowski_bannon_trump_pardons/
[9] https://whitepapers.theregister.com/
Re: A bit of an Intel fail
“fails very much on document control” that does seem to be the case. But I find it hard to believe Intel would not have put him on gardening leave for the period of his notice and locking him out of their systems the moment he told them he was going to leave.
If that is the case and the files were taken after he told Intel he was going to leave it looks like he did not originally plan to take the files when he left. If he were planning to take the files surely, he would have done that before announcing he was leaving when he knew he still had access to them. Not condoning the theft but looks like a crime of opportunity.
Air gapped espionage
He should've taken photos of his laptop screen with a film camera. Very old school but a leaves no digital trail.
Impressive forensic capabilities
Impressive forensic capabilities, no shit Sherlock bloody impressive. Not only could they tell what make of USB drives were connected but also which files were downloaded to which drives.
With those forensic capabilities and the highly confidential information they knew the soon to be ex-employee had access to hence the confidentiality agreement. I would have thought they would have checked to see what he had downloaded before he signed and left. I am not saying Intel security was lax maybe it would be deemed out of order to do that kind of forensic check, an invasion of privacy.
Really...?
"If nothing else, this tells us that Microsoft and Intel both have some impressive forensic capabilities."
Most enterprise Endpoint security suites* can log and control USB devices based on vendor ID's, serial numbers, etc - and log all files copied. (It might also be natively possible in Windows...)
Some customers only approve encrypted drives, only approving drives from a specific manufacturer, only approving drives with known and approved (by IT) serials, or combinations of the above to absolutely block unapproved devices and prevent breaches. (Same with Cloud Storage.)
More of an abuse of trust, than a technical failure...
*Anon as I work for such a vendor.
Re: Really...?
Seems impressive to those of us not in the know. :)
I just a programmer and "enterprise Endpoint security suites" are not in my area. But I do now consider myself forewarned and for that have an up vote.
So these amazing companies...
...still don't have a fucking clue about basic document security i.e. stop external drives being plugged in.
Maybe they could use McAfee to stop this sort of thing? Or maybe Group policies?
Nah, just let them do what they want.
MAC address
I'm thinking that all that has to happen is to capture the MAC address of any device mounted on the network - the [1]OUI prefix gives you the manufacturer, and it could probably be narrowed down to a specific device instance with the assistance of the OEM. See, e.g., [2]Wireshark OUI Lookup Tool
[1] https://standards.ieee.org/faqs/regauth.html#17
[2] https://www.wireshark.org/tools/oui-lookup.html
By this time Intel had asked Microsoft for help. The Windows giant, we're told, discovered the first drive had been used within its walls, including on Gupta’s Microsoft-issued PC.
Is anyone else surprised that MS didn't block USB drives? I'm assuming there's someone in the company who knows how to do it...
A bit of an Intel fail
Someone is leaving after 10 years who has access to "a trove of confidential documents" and you still allow totality free access to them on their last day of employment. At best they should have been on gardening leave with the very least they should have done is restrict their access to files towards the end of their notice.
Intel may have "some impressive forensic capabilities" but it fails very much on document control.