Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

191–200 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#191

Earlier quoted context omitted.

What's wrong with full disclosure? Ryzen owners ought to be informed ASAP that they're (possibly) vulnerable.

What can AMD do with 24h notice? Could they even verify the veracity of the claim in that time? As am AMD system owner, I would much prefer that big flaws were disclosed in a coordinated manner with AMD - giving them a fair chance to verify and find a solution, rather than giving bad actors a head start.

Depends on the flaw, might give them long enough to make a fix [1] (they might have one in the pipeline, or one they kept from release because of effects on speed, you never know) but more than likely gives them long enough to decide _how_ to handle it.

[1] I'm partially recalling a fix, on Facebook I think, that was implemented within a few hours of reporting; it was ac testing API that got exposed. Different field, of course.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#192
post #188

Earlier quoted context omitted.

What if it's not false but misleading? That sounds closer to what they are doing here. Sure they included a ridic disclosure agreement that you apparently agree to have read if you continue to read their webpage, and it says something along the lines of "this is our opinion". It feels slimy and gross.

"Slimy" and "gross" are not nearly sufficient for either insider trading or market manipulation. I don't particularly like the way these researchers are acting either, but that's actually because I don't like vulnerability impact being exaggerated and over-hyped. The other stuff doesn't bother me too much. If the news pushing a stock price is so misleading that it's categorically different from the truth, then I coul…

I was just relaying my feelings in that last bit. But the misleading bit in my comment specifically refers to the fact it's an exaggeration as you put it. So you can flash a bios and make it do nefarious things: that is a true statement but it's hardly a "security flaw" and almost not even too surprising. They are however taking a flaw and spinning it out to be the massive security flaw which it isn't.

I guess that's my question. If you take a true statement and put it out with connotations that it's actually a terribly thing and worse than it is, just being "true" doesn't matter. Stupid analogy, say you go to a bakery and buy bread, then it goes stale in two hours or so by the time you get home. Then you go and write a negative yelp review that this bakery is terrible at baking and they sell subpar bread. You just don't know that the bakery doesn't bake in preservatives that bread you buy from the supermarket does. And it certainly isn't like the bakery is selling spoiled/poisoned bread or selling rocks painted to look like bread loaves.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#195

Earlier quoted context omitted.

No, they are not "shunned by the infosec community", no matter how nice that narrative sounds to you.

No need for the attitude. Just take a look on twitter at what prominent members of the community are saying - they are not impressed with this behaviour. I'm also a member of that community, and hold the same view. The vast majority of the infosec community promote coordinated disclosure.

If you're referring to vulnerability research twitter, and not, I don't know, IT security twitter, then no that's not what's happening.

The CTS-Labs people are taking shit from vulnerability research twitter for overhyping the findings (meaning: they released a report on a day ending in "y"). People are noting the connection to the short selling --- but since this will be the 3rd or 4th time someone has very publicly done that, I don't see anybody shocked or outraged by it.

But this public ostracism you referred to --- specifically the notion that dropping vulnerabilities with 24 hours notice would reliably generate it --- is fictitious. I'm not sure how you can be a part of the vulnerability research community and believe that there is public shunning attached to dropping zero-days, since many of the best known people in the community have repeatedly done exactly that.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#196
post #93
post #90

Earlier quoted context omitted.

You can consult the search bar at the bottom of the page to learn that I am 100% OK with immediate, uncoordinated disclosure. It's not what I personally do, but that's easy for me to say because I don't find these kinds of vulnerabilities. This isn't "shoot the hostages". The researchers didn't manufacture the vulnerabilities; AMD did. If 4 dudes in a basement can find exploitable driver vulnerabilities, so can 10 re…

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…

> you are a better person than that

I don't think this is an appropriate way to argue. Sounds like if he disagrees with you, he is somehow below standard.

> It's just...minimal decency, to care about other people.

Alerting folks to the danger that they face is one way to do so. Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remove themselves from harm.

As another note, why not argue for Responsible Development? This is where the outcry should be. Flaws in products come about because they are shipped before they are finished.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#198
Amazing coincidence!

On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations.

Headline:

>We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries.

Viceroy Research lists no employees or contact address, but it appears they are not a crack team of hardworking & incisive business analysts, but two Australian teenagers and a former UK child social worker, struck off in 2014 for misconduct.

They have previous form in producing or plugging short-call stories (quite effectively), and latterly investigated by South African media for similar shady business.

https://www.moneyweb.co.za/in-depth/investigations/viceroy-u...

It took very little internet sleuthing to find this stuff out. None of the tech press bothered to do so.

Disclaimer: I have no position in AMD.

Edit: link to Viceroy https://viceroyresearch.org/

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#199

Earlier quoted context omitted.

So the 11 billion dollar vendor who shipped vulnerabilities in the first place gets to treat these problems as an externality, but 4 dudes in a basement who did a basic research project have to be restrained from speaking? I don't see how you get there from here.

I don't get how you get to me thinking the vendor gets to treat these problems as an externality? I am all in favor of slagging vendors who release buggy shit. For hardware (and some software) manufacturers I'd be in favor of significant legal remedies available to people who purchase hardware later found to contain security vulnerabilities. But I think that should be done after mitigations are in place to protect en…

I don't understand the chronology you're working from. The timeline here shouldn't start from "when the independent researchers find something in their basement". It should, rather, start from "when the first MRD for the product is sent from the PM to the development team". That's when the clock starts ticking on mitigation. AMD had years.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#200
post #63

Earlier quoted context omitted.

No, I'm just noticing again that people who don't don't do a lot of vulnerability research have a lot of interesting opinions about the professional norms of people who do that work. But you never know --- maybe they do a lot of research, in which case, yes, their opinion on security research norms is a lot more interesting to me.

I am not a security researcher, and I do not speak for the person you are replying to, but I do believe that Intel's documented history of unethical, anticompetitive practices against AMD, for example, deliberate compiler handicapping for non Intel CPUs[1], is enough evidence to establish at least some suspicion regarding these results, especially considering the short warning given to AMD before public disclosure. I…

I'm not arguing about Intel. If you think this is a giant conspiracy by Intel, more power to you --- I'm not engaging further on that.
Post reply on HN