I found this on /r/AMD haha: https://i.imgur.com/OkWlIxA.jpg
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
171–180 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#17224 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#173Earlier quoted context omitted.
There is a reasonably accepted definition for what a "black hat" is. I don't particularly agree with conceptually bucketing people into black hats or white hats, but the paradigm has an existing meaning. In any case, if we go by what you're saying, then anyone can define "black hat" to mean whatever they want, which means it's a meaningless and unproductive concept to throw around in conversation. Your assertion is i…
There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith.
Speaking as someone who 1) works in the security industry, 2) has managed corporate disclosure programs as an internal security engineer, 3) has run a security consulting firm working with many companies, and 4) has reported security vulnerabilities in disclosure programs; no, that's not the reasonably accepted definition. I can't think of any colleague I've ever worked with off the top of my head, nor any widely read security-focused periodical (like Krebs), who would use the term "black hat" for such a generalized disagreement of ethics.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#174Earlier quoted context omitted.
This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.
> They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Seriously. AMD stock is trading up 3+% at the time of my comment, and it's climbed since the disclosures this morning. Something tells me this backfired. Discl: I've been long AMD for a long frickin' time.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#175Earlier quoted context omitted.
There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith.
> There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith. Speaking as someone who 1) works in the security industry, 2) has managed corporate disclosure programs as an internal security engineer, 3) has run a security consulting firm working with many companies, and 4) has reported security vulnerabilities in disclosure programs; no, that's not…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#176Earlier quoted context omitted.
It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.
There is far far more incentive for AMD and its partners to understate the severity.
AMD isn't going to crash and burn over these flaws anymore than Intel (at 5 year high) did.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#177Earlier quoted context omitted.
It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.
There is far far more incentive for AMD and its partners to understate the severity.
So, AMD has vastly more incentive to be accurate than short sellers.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#178Earlier quoted context omitted.
Basically a follow the money situation. Could something like this be considered inside information? Or is it legal to actively manipulate stock prices to ones benefit in this way?
> Could something like this be considered inside information? No, illegal insider trading refers to trading on inside information when you have a confidentiality agreement or a fiduciary duty. Information asymmetry is insufficient (or else it would be virtually impossible to profitably trade at all). > Or is it legal to actively manipulate stock prices to ones benefit in this way? The way you're presenting this is a…
It feels slimy and gross.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#179Earlier quoted context omitted.
If it's actually someone attempting to make money on a short or to benefit from a working relationship with a competitor, then a bug bounty program does nothing. No one can run a bounty program that pays out anywhere near as much as the information is actually worth to an adversary. Bug bounties work to engender a bit of good will among researchers and to provide some incentive to an otherwise neutral party to play b…
Not unless the bounties are large enough to attract the attention of a hedge fund.
Which they should be if the alternative is a much larger loss to the company's share value. The shareholders come out ahead to pay five million on a bug bounty if the alternative is to lose a billion dollars in market cap.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#180Earlier quoted context omitted.
> "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before. Individuals sometimes do this, security companies very rarely - and both are shunned by the infosec community at large when they do so, as this is very unethical behaviour. They registered the domain a couple of weeks ago - why give AMD only 24 hours notice? In this case it does seem highly likely there is some stock market skulld…
No, they are not "shunned by the infosec community", no matter how nice that narrative sounds to you.
Just take a look on twitter at what prominent members of the community are saying - they are not impressed with this behaviour. I'm also a member of that community, and hold the same view.
The vast majority of the infosec community promote coordinated disclosure.