24hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.
Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
151–160 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#152I think the economics/ethics of the researchers are overshadowing something big: "RYZENFALL allows malicious code to take complete control over the AMD Secure Processor." "Multiple vulnerabilities in AMD Secure Processor firmware allow attackers to infiltrate the Secure Processor." If this is legitimate, this is huge! The PSP could potentially be disabled! Very little work has gone into handicapping the PSP compared…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#153Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#154Earlier quoted context omitted.
No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.
There is a reasonably accepted definition for what a "black hat" is. I don't particularly agree with conceptually bucketing people into black hats or white hats, but the paradigm has an existing meaning. In any case, if we go by what you're saying, then anyone can define "black hat" to mean whatever they want, which means it's a meaningless and unproductive concept to throw around in conversation. Your assertion is i…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#155Earlier quoted context omitted.
No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.
This is what wikipedia says: A black hat hacker (or black-hat hacker) is a hacker who "violates computer security for little reason beyond maliciousness or for personal gain" The personal gain part certainly fits with short selling the stock.
If we can call them "hackers" just because they ostensibly compromised their own hardware or software as a proof of concept for the vulnerability research, does that mean that all of Google's Project Zero consists of hackers and black hats because they get paid (personal gain) by Google to find security vulnerabilities?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#156> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time. 90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional. Full, immediate disclosure is responsible.
And the users downstream of bugs that are made more widely vulnerable--because, as anyone who saw how, as an example, previously rare MitM attacks became commonplace after Firesheep etc. were publicized, obscurity is in fact a component of security --are...? Well, fuck 'em, I guess. Responsible disclosure, contrary to the super-cool leet kid notions expressed by people with who choose to exhibit an underdeveloped soc…
1. All of the relevant people, i.e. "the users downstream of bugs" are already vulnerable.
2. It's possible, maybe even probable (or likely), that people, other than the researchers that are disclosing the vulnerability, have also discovered the same vulnerability and, furthermore, that those others can exploit the vulnerability.
3. Every delay in disclosing the vulnerability prevents the victims from protecting themselves from any bad actors mentioned in [2] thru means more drastic than applying a patch or similar from the relevant vendors (e.g. taking the affected components offline or otherwise making them unavailable).
The argument hinges on the probable size of the bad actors mentioned in [2]. If you assume that the disclosing researchers are the first people to discover the vulnerability, then it would possibly be best for them to first disclose the vulnerability to the relevant vendor or vendors. But note that even vulnerabilities disclosed to vendors can be leaked to bad actors.
And if you don't assume that the disclosing researchers are the first people to discover the vulnerability, then not disclosing ASAP prevents people from protecting themselves.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#157This is FUD. The original post was flagged, because the domain and website are far from trustworthy. Technically, the accusations seem to be more of a joke. Hello, Intel?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#158Earlier quoted context omitted.
This is what wikipedia says: A black hat hacker (or black-hat hacker) is a hacker who "violates computer security for little reason beyond maliciousness or for personal gain" The personal gain part certainly fits with short selling the stock.
Excellent, great citation! Now, precisely what did the security researchers hack for their own gain, and precisely which computer's security was violated? If we can call them "hackers" just because they ostensibly compromised their own hardware or software as a proof of concept for the vulnerability research, does that mean that all of Google's Project Zero consists of hackers and black hats because they get paid (pe…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#15924hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.
Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.
Individuals sometimes do this, security companies very rarely - and both are shunned by the infosec community at large when they do so, as this is very unethical behaviour.
They registered the domain a couple of weeks ago - why give AMD only 24 hours notice?
In this case it does seem highly likely there is some stock market skullduggery afoot.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#160Earlier quoted context omitted.
Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.
It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.