Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

151–160 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#151
post #21

24hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

They had all the marketing material available and ready to go (and I bet that took more than 24 hours to make). The 24 hr notice is just an out against the usual accusation of publishing an exploit without giving notice. They sure well knew AMD couldn't even verify it in 24hrs, allowing them to get the full publicity while coming off as a reputable security firm.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#152

I think the economics/ethics of the researchers are overshadowing something big: "RYZENFALL allows malicious code to take complete control over the AMD Secure Processor." "Multiple vulnerabilities in AMD Secure Processor firmware allow attackers to infiltrate the Secure Processor." If this is legitimate, this is huge! The PSP could potentially be disabled! Very little work has gone into handicapping the PSP compared…

Is it wrong that my immediate reaction to that was "Wait, isn't/wasn't the PSP a portable? Did they actually use x86/x64 AMD processors in those? How?? AMD's traditionally been poor on power management!"

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#154
post #134

Earlier quoted context omitted.

No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.

There is a reasonably accepted definition for what a "black hat" is. I don't particularly agree with conceptually bucketing people into black hats or white hats, but the paradigm has an existing meaning. In any case, if we go by what you're saying, then anyone can define "black hat" to mean whatever they want, which means it's a meaningless and unproductive concept to throw around in conversation. Your assertion is i…

There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#155
post #122

Earlier quoted context omitted.

No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.

This is what wikipedia says: A black hat hacker (or black-hat hacker) is a hacker who "violates computer security for little reason beyond maliciousness or for personal gain" The personal gain part certainly fits with short selling the stock.

Excellent, great citation! Now, precisely what did the security researchers hack for their own gain, and precisely which computer's security was violated?

If we can call them "hackers" just because they ostensibly compromised their own hardware or software as a proof of concept for the vulnerability research, does that mean that all of Google's Project Zero consists of hackers and black hats because they get paid (personal gain) by Google to find security vulnerabilities?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#156
post #19
post #5

> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time. 90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional. Full, immediate disclosure is responsible.

And the users downstream of bugs that are made more widely vulnerable--because, as anyone who saw how, as an example, previously rare MitM attacks became commonplace after Firesheep etc. were publicized, obscurity is in fact a component of security --are...? Well, fuck 'em, I guess. Responsible disclosure, contrary to the super-cool leet kid notions expressed by people with who choose to exhibit an underdeveloped soc…

Here's the strongest version of the claim that I understand:

1. All of the relevant people, i.e. "the users downstream of bugs" are already vulnerable.

2. It's possible, maybe even probable (or likely), that people, other than the researchers that are disclosing the vulnerability, have also discovered the same vulnerability and, furthermore, that those others can exploit the vulnerability.

3. Every delay in disclosing the vulnerability prevents the victims from protecting themselves from any bad actors mentioned in [2] thru means more drastic than applying a patch or similar from the relevant vendors (e.g. taking the affected components offline or otherwise making them unavailable).

The argument hinges on the probable size of the bad actors mentioned in [2]. If you assume that the disclosing researchers are the first people to discover the vulnerability, then it would possibly be best for them to first disclose the vulnerability to the relevant vendor or vendors. But note that even vulnerabilities disclosed to vendors can be leaked to bad actors.

And if you don't assume that the disclosing researchers are the first people to discover the vulnerability, then not disclosing ASAP prevents people from protecting themselves.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#158
post #155

Earlier quoted context omitted.

This is what wikipedia says: A black hat hacker (or black-hat hacker) is a hacker who "violates computer security for little reason beyond maliciousness or for personal gain" The personal gain part certainly fits with short selling the stock.

Excellent, great citation! Now, precisely what did the security researchers hack for their own gain, and precisely which computer's security was violated? If we can call them "hackers" just because they ostensibly compromised their own hardware or software as a proof of concept for the vulnerability research, does that mean that all of Google's Project Zero consists of hackers and black hats because they get paid (pe…

Project Zero practices responsible disclosure. They do not make money from the exploitation of the companies whose software/hardware they find flaws in. The difference is very stark and you are being deliberately obtuse.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#159
post #21

24hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

> "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

Individuals sometimes do this, security companies very rarely - and both are shunned by the infosec community at large when they do so, as this is very unethical behaviour.

They registered the domain a couple of weeks ago - why give AMD only 24 hours notice?

In this case it does seem highly likely there is some stock market skullduggery afoot.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#160
post #137

Earlier quoted context omitted.

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.

There is far far more incentive for AMD and its partners to understate the severity.
Post reply on HN