Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

51–60 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#51
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

Mentioned in another comment, but from their management page: http://www.cts-labs.com/management-team

> He [Yaron, CFO] is also the founder and Managing Director of NineWells Capital, a hedge fund that invests in public equities internationally.

I wonder how linked the companies are - is this basically a vulnerability research company as a research arm of a hedge fund?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#52
post #5

> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time. 90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional. Full, immediate disclosure is responsible.

Not allowed to say that here.

You're allowed to say plenty of wrongheaded things here and elsewhere on the Internet.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#54
post #33
post #22

Earlier quoted context omitted.

Seeing as CTS-Lab's CFO also founded a hedge fund you're probably on the right track. >Yaron co-founded CTS-Labs in 2017, and previously served as an intelligence analyst in the Israeli Intelligence Corps Unit 8200. He is also the founder and Managing Director of NineWells Capital, a hedge fund that invests in public equities internationally. He holds a B.A. and M.A. from Yale University.

Basically a follow the money situation. Could something like this be considered inside information? Or is it legal to actively manipulate stock prices to ones benefit in this way?

No. Doing independent research is not “inside information”. This is actually pretty close to how a market is supposed to work.

It’s also not market manipulation to publish factual information or opinions. Only knowingly publishing false information would qualify.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#55
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

AMD's stock was negative multiple times today ($11.38 on March 13, 2018 10AM,and at 12Noon on NASDAQ). Shorting the stock would be an obvious play. I have heard of people thinking about trading on security flaws in products but never seen it done in real life.

There is also some questionable research group involved in all of this: https://viceroyresearch.org/2018/03/13/amd-the-obituary/

It's not uncommon for short sellers to take a position first before releasing a report like this to drive the stock lower. Of course, there are legitimate groups that, in the past, have unearthed real issues and corporate misconduct, but there are also questionable groups that will release reports with little to no substance. This case certainly does looks dubious, but I'd like to see an assessment by reputable security expert.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#56
post #5

> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time. 90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional. Full, immediate disclosure is responsible.

And at other times 90 days maybe inadequately short. But 90 is just a round number someone at Google thought is a good idea. And now it's become 'standard'. I can go with immediate, or I can go with never. But realize that every vuln is different, and their impact (or hardship of writing or applying patches) may not always be fully understood by stakeholders involved before or immediately after the details are releas…

90 days is good amount of time to research a vuln and prepare fixes.

We could always have the government regulate this instead though, instead of being professionals and self-regulating.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#57
If the vulnerabilities were real, I'd have no problem with a company using it to promote themselves, trade and talk their book, etc. The issue here is the vulnerabilities are very overhyped (some are fundamental things like "if you reflash your BIOS with evil, you're screwed", some just make local root access more persistent, etc.

The problem with something like TRO LLC is that markets don't move on security info.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#58
post #21

24hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

He did say “should” disqualify someone from employment, which I read as “ought to.” Idealism maybe. But with black or gray hat research, you’re right.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#59
post #21

Earlier quoted context omitted.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

Perhaps this is my ignorance, but I was under the impression that security disclosures are usually tightly coordinated to minimize exposure of innocent users. > "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before. Could you point me to an example of a zero warning disclosure that exposed a large amount of users without first attempting to coordinate with the responsible party?

Some researchers coordinate, some researchers don't. For a project originally organized around the principle of getting not just research results but functioning exploit code deployed regardless of vendor preparedness, look no further than Metasploit.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#60
post #32

Earlier quoted context omitted.

This is so fishy to me, it's so unprofessional of a security researcher. My tinfoil hat is already rattling...

Have you done a lot of published security research?

Nice non-sequitur. Somehow the limiting factor on the ability of someone to judge professionalism is the number of papers they've written?
Post reply on HN