Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

111–120 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#111
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

This is too well organized and presented.

For what?

My guess is that this has to be financed in some part by a group of short-sellers.

What evidence do you have of that other than 'too well presented'? It sounds like a conspiracy theory, not a guess.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#112
post #74
post #33

Earlier quoted context omitted.

Basically a follow the money situation. Could something like this be considered inside information? Or is it legal to actively manipulate stock prices to ones benefit in this way?

> Could something like this be considered inside information? No, illegal insider trading refers to trading on inside information when you have a confidentiality agreement or a fiduciary duty. Information asymmetry is insufficient (or else it would be virtually impossible to profitably trade at all). > Or is it legal to actively manipulate stock prices to ones benefit in this way? The way you're presenting this is a…

Might the latter also depend on how you present it?

As far as I can see this is only an exploit of secure boot if you are already on ring 0 level auth. Making a whole webpage with lots of graphics and whatnot, sending press releases all over and in general present it like a security flaw on the level of meltdown seems .. false?

Probably court level material.. In any case it seems to have backfired as the stock is up.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#113
post #78

Earlier quoted context omitted.

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

A new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices…

Citron Research? Total hack and the premise that they provide the market a value is a stretch at best. Sometimes right and lots of times incredibly wrong but makes money on investors panicking immediately.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#114
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on.

This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company

For example, a short seller last year revealed (through extensive research), that Valeant Pharmaceuticals was stuffing its channels and faking its finances. He placed a huge sort sell and went public with the damaging info - tanking the stock from $270 to $12 and made a ton of profit off of it: https://www.nytimes.com/2017/06/08/magazine/the-bounty-hunte...

Without this incentive, why would anyone bother to reveal damaging info? You're placing your self as a target with no reward. The payment is the natural balance of the market.

So yes, this research firm is connected w a hedge fund, and they have a very vested interest. But that doesn't make their claim untrue

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#115
post #70

Earlier quoted context omitted.

It's not unheard of in the sense of never having happened, but it is a clear breach of ethics for a security researcher. (The term for not doing what these guys did is "responsible disclosure").

If you put 10 people who find and publish security vulnerabilities professionally in a room, I do not think you would secure agreement that this is a "clear breach of ethics". There are extremely well-known researchers who have made a point of not coordinating with vendors; vendors, historically, have been far more abusive than researchers.

But security researchers don't exist in a vacuum: they're part of larger society. If the security researcher subgroup has a code of ethics that diverges too far from the popular perception of what their code of ethics should be, I could see popular pressure to bring them into alignment (all the way up to using the legal system).

I'm not saying the non-security researcher users on HN have an opinion representative of the public as a whole, but this comment and a previous question asking another user what security research they've published may point to such an ethics disconnect between security researchers and the broader populace -- or simply a disregard for the concerns of the broader populace. I think it would be beneficial for security researchers (or any professional group) to listen to ethics concerns of the broader group they're a part of.

On another note, I would also assert that abusive actions by vendors do not excuse abusive actions by researchers (and vice-versa).

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#116
post #80

Earlier quoted context omitted.

AMD's stock was negative multiple times today ($11.38 on March 13, 2018 10AM,and at 12Noon on NASDAQ). Shorting the stock would be an obvious play. I have heard of people thinking about trading on security flaws in products but never seen it done in real life.

I've done it once or twice when I reported a vulnerability directly to a company and I knew they'd have to report it to downstream customers pretty quickly. I've also been in discussions for larger vulnerabilities with security-focused hedge funds such as Muddy Waters. Generally I'm weakly skeptical about profiting from it consistently. In particular, funds like Muddy Waters have a pretty high bar for the sort of vul…

[deleted]

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#117
post #91
post #77

Earlier quoted context omitted.

What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html

Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...

Btw, your HN search result page links to all of the references that you THINK what the term "Responsible disclosure" means. Be it "coordinated disclosure" or whatever else, I don't care. But I don't think it's ethical to disclosure the security vulnerabilities to the wild without contacting the vendor and given them a timeline (should be MUCH LONGER than 24 hours) and the benefit of doubt first.

Hypothetically speaking, if you are researching vulnerabilities solely for the intent of money (because you can sell to them to 3rd parties or your side hedge fund business can profit from disclosures in the stock market) then shame on you, because you are doing the society a dis-service and gaining on everyone' losses. To me, you are as evil as those hacker who utilize them.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#118
post #114
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#119
post #93

Earlier quoted context omitted.

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…

I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…

This is probably where we diverge. From where I stand, "end users" are incapable of making a meaningful decision about security at this level. It would be awesome if they weren't, and god knows I have spent a decent amount of time in my life trying to bootstrap people into such a position, but it doesn't...like...work. There is a computing priesthood, as much as we have tried to democratize this stuff, and it's all goddamn nonsense to those outside of it. The set of people I know who do not actively work in tech and can make meaningful decisions about the technology they work with is...my girlfriend, probably. Can't really think of anyone else who isn't reliant on "do this" the advice of others, whether it's correct or not.

Continued education to help end users get to the point where they can make meaningful and educated decisions is great, and should be pursued, and I do it where I can (though most of the time there's just a shrug and a "whatever"). But, barring that, somebody's gotta make choices on their behalf, and there's a Jerry Garcia quote for this one, you know? With great power comes great responsibility, and we gave ourselves that power. And, outside of a security context, this is why I unflinchingly come down on people who work for shit companies that hurt people, why I'd never hire someone who worked for, say, a toolbar vendor in the 90's/00's and why I have fired clients before when I discovered they were doing shitty things with data gleaned from people who trust them: because we have ethical responsibilities to the people downstream of us who are ill-equipped to make meaningful, educated decisions. I can't compel anyone to do as I do--but I can say that one should, because it's decent.

I can't agree that the power switch is a reasonable mitigation in 2018. In the nineties, sure, but too much of life revolves around this garbage we invented and keep mostly creaking along. (Should it? Probably not. Does it? Yeah.) We are on a ratchet, we can't go back, and kicking the decision down to people who literally-literally lack the tools to make a wise decision while painting a target on them for bad actors who can take advantage of them is profoundly disturbing to me.

This particular vulnerability is a post-compromise privilege escalation flaw, yes. But it strikes me that the conversation must be bigger than that, because the same arguments are used for both. This? Low stakes. Heartbleed? Incalculably high stakes. But the same argument could/would (if it were found by shitheads rather than people with a certain amount of decency to them) be used for the latter instead of the former, and that's what makes me itch.

(And to be clear, irrespective of this conversation, you know I am a big fan.)

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#120
post #106
post #98

Earlier quoted context omitted.

These guys are essentially more black hat than white hat

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

If the term is flexible, why the hard reaction to my flexing of it?

I agree with the sibling commenters here. This is a bad faith, financially-motivated disclosure with insufficient time given to AMD to react

Post reply on HN