Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

201–210 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#201
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

From "Viceroy Research": >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Direct quote from: https://viceroyresearch.files.wordpress.com/2018/03/amd-the-... These guys are slimy as hell, this is disgusting.

At what point does it go from being legal (utilizing information that anyone could have discovered with enough time and effort, whether through short sale or investment) to illegal (stock manipulation through rumor or innuendo)? This qualifies in my eyes, but it's probably hard to prove when one is attached to the other. I agree, it does feel slimy.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#202

Earlier quoted context omitted.

Here's the strongest version of the claim that I understand: 1. All of the relevant people, i.e. "the users downstream of bugs" are already vulnerable . 2. It's possible, maybe even probable (or likely ), that people, other than the researchers that are disclosing the vulnerability, have also discovered the same vulnerability and, furthermore, that those others can exploit the vulnerability. 3. Every delay in disclos…

I think that is a fair depiction. I think also that [3] requires that people are capable, en masse, of protecting themselves from those bad actors. I think a cursory look at the world indicates that this is not even adjacent to reality.

I think your perspective is a bit narrow. If you consider each individual person, [3] is indeed nonsense. However, the impact of many hacks comes disproportionally from high-value targets.

Some high-value targets (e.g. key infrastructure, parts of government, major enterprises) have dedicated security teams, and can come up with a pretty decent response if given the appropriate information. Divulging vulnerability information widely, in particular, may or may not be a net benefit to them. (Consider e.g. Linux vendor vulnerability lists.)

Other high-value targets (e.g. journalists, human-rights activists, etc.) are utterly outgunned by their adversaries (who can afford to buy or find new vulnerabilities), and can only hope that something causes vendors to consistently write software that's sufficiently-uneconomic to exploit. In the sufficiently-long run, proponents of full disclosure would argue, anything that increases the cost of shipping vulnerable software should help these users.

(Disclaimer: absolutely not speaking for my employer here.)

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#203
post #78

Earlier quoted context omitted.

A new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices…

Just look at what Citron Research did to Shopify last year. They tanked the stock from $120 to $93 just based on false accusations that they put out in a "report". Now Shopify is now closer to $150...so their plan worked.

> just based on false accusations that they put out in a "report".

If it's false information, isn't that classic stock manipulation? I thought for it to be legal to make money on the stock it had to be both accurate and publicly available (if potentially hard to put together)?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#204
post #93

Earlier quoted context omitted.

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…

I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…

> These vulnerabilities are all post-compromise privilege escalation flaws

I would say they are all invasive evil maid threat vectors. Each one requires either physical access to the hardware or (as you stated) an already established root privileges. We all know that if you have physical access to hardware, it's essentially game over.

However. One of the vulnerabilities supposedly allowed to subvert UEFI secure boot. If that's true and allows to boot arbitrary media, then the others are equally feasible, because an attacker can boot into a root shell of their choosing.

The timing in this disclosure reeks of malice, though. Giving a 24h advance warning basically allows the outfits to claim that they disclosed vulnerabilities to manufacturer before going public. Technically true. Just highly misleading and dishonest.

I have personally no beef with full disclosure, and have advocated it as a viable mechanism since the mid 1990's. I also happen to think that responsible disclosure is a good approach, but it definitely needs the threat of FD as a stick, because otherwise vendors would not have any real incentives to work on addressing security bugs. Name-and-shame does work.

Let's get back to AMD flaws. Giving a really short window? Basically just enough to have an initial PR response ready? Have the decency to go full disclosure. Or give a full month. AMD won't be fixing the bugs before news breaks in either case. Just don't claim this is anything but a maliciously crafted exercise with ulterior motives.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#205
A security researcher claims to have access to the full (non-public) technical report as well as PoC exploits for it. He says they're legit, and they are flaws, not just "you can do admin things with an admin password".

https://twitter.com/dguido/status/973628511515750400

Sounds like the capabilities include the ability to jump outside a VM sandbox, take over the PSP, and pivot to the firmware or BIOS exploits.

https://www.techpowerup.com/242328/13-major-vulnerabilities-...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#206

Earlier quoted context omitted.

This is probably where we diverge. From where I stand, "end users" are incapable of making a meaningful decision about security at this level. It would be awesome if they weren't, and god knows I have spent a decent amount of time in my life trying to bootstrap people into such a position, but it doesn't...like...work. There is a computing priesthood, as much as we have tried to democratize this stuff, and it's all g…

So the 11 billion dollar vendor who shipped vulnerabilities in the first place gets to treat these problems as an externality, but 4 dudes in a basement who did a basic research project have to be restrained from speaking? I don't see how you get there from here.

An eye for an eye works only until everyone is blind.

You seem to have several deeply misguided premises.

1. We don't know ARM knowingly shipped these chips although they were vulnerable. Bugs happen.

2. Even if this was the case, an individual can show, and ought to, show decency and empathy towards others.

3. This last comment of yours is a straw man and I doubt you are incapable of seeing this. You parent's argument was much more nuanced and elaborate than your rebuttal.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#207
post #204

Earlier quoted context omitted.

I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…

> These vulnerabilities are all post-compromise privilege escalation flaws I would say they are all invasive evil maid threat vectors. Each one requires either physical access to the hardware or (as you stated) an already established root privileges. We all know that if you have physical access to hardware, it's essentially game over. However . One of the vulnerabilities supposedly allowed to subvert UEFI secure boot…

While I'm fine with criticizing them for partial disclosure, I again have a problem mapping any of this back to ethics, because, again, independent researchers do not have an obligation to vendors or to any amorphous public. As long as they aren't literally exploiting (or arranging to have exploited) vulnerabilities to break into people's computers, or lying about what they found, I don't think ethics have much to say about what they should do.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#208

Earlier quoted context omitted.

I think that is a fair depiction. I think also that [3] requires that people are capable, en masse, of protecting themselves from those bad actors. I think a cursory look at the world indicates that this is not even adjacent to reality.

I think your perspective is a bit narrow. If you consider each individual person, [3] is indeed nonsense. However, the impact of many hacks comes disproportionally from high-value targets. Some high-value targets (e.g. key infrastructure, parts of government, major enterprises) have dedicated security teams, and can come up with a pretty decent response if given the appropriate information. Divulging vulnerability in…

Nobody appointed these security researchers to the authority to which you assign to their actions, though. Burning the immediate user on the off chance that it helps the hypothetical future user is some very weak tea.

I agree that some proponents of immediate disclosure would claim that their actions encourage vendors to ship less vulnerable hardware or software. I do not believe that that, in the general case, is why it is being done. And I am certain that that, in this specific case, is not why it was done.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#209

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

I even thought Meltdown/Spectre was overblown, and the average user will never see these attacks.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#210
post #114

Earlier quoted context omitted.

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

It's not their problem. There's no obligation for them to give any warning at all. They can just go public, short the stock, and watch it fall. The warning is just a polite thing to do
Post reply on HN