Earlier quoted context omitted.
Might the latter also depend on how you present it? As far as I can see this is only an exploit of secure boot if you are already on ring 0 level auth. Making a whole webpage with lots of graphics and whatnot, sending press releases all over and in general present it like a security flaw on the level of meltdown seems .. false? Probably court level material.. In any case it seems to have backfired as the stock is up.
I think the difference in facts you're talking about is a difference of degree, not category. In other words, it's not plainly false, there certainly is a vulnerability, it's just perhaps exaggerated. I could see a case being brought against the researchers on those grounds, but I'd be really surprised if anything came of it.
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
211–220 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#212>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…
You mean to tell me my machine can be exploited if I let someone do one of the following. 1. Flash the BIOS 2. Have admin access Holy shit, this calls for a full fledged panic! I am very disappointed anandtech.com even bothered to give this smear campaign the time of day. If someone can flash your BIOS or has admin access then you already have way bigger problems.
Anandtech is reporting on the situation more than the flaws. That does require covering what the flaws are though. Not covering it at all isn't exactly performing good journalism either.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#213Earlier quoted context omitted.
Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.
It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.
Short sellers want the opposite. So they both present their best cases and let the public decide, much like how lawyers will defend their own clients to the last breath regardless of the amount of evidence against them
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#214Earlier quoted context omitted.
So the 11 billion dollar vendor who shipped vulnerabilities in the first place gets to treat these problems as an externality, but 4 dudes in a basement who did a basic research project have to be restrained from speaking? I don't see how you get there from here.
An eye for an eye works only until everyone is blind. You seem to have several deeply misguided premises. 1. We don't know ARM knowingly shipped these chips although they were vulnerable. Bugs happen. 2. Even if this was the case, an individual can show, and ought to, show decency and empathy towards others. 3. This last comment of yours is a straw man and I doubt you are incapable of seeing this. You parent's argume…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#215>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…
For example, a short seller last year revealed (through extensive research), that Valeant Pharmaceuticals was stuffing its channels and faking its finances. He placed a huge sort sell and went public with the damaging info - tanking the stock from $270 to $12 and made a ton of profit off of it: https://www.nytimes.com/2017/06/08/magazine/the-bounty-hunte....
Without this incentive, why would anyone bother to reveal damaging info? You're placing your self as a target with no reward. The payment is the natural balance of the market.
So yes, this research firm is connected w a hedge fund, and they have a very vested interest. But that doesn't make their claim untrue
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#216Earlier quoted context omitted.
No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.
No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.
To save the click: "1. [common among security specialists] A cracker, someone bent on breaking into the system you are protecting."
Your (and hdyr's) looser version is not in common usage and in that sense is wrong.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#217https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"
People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#218Earlier quoted context omitted.
No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.
Words aren't defined by any authority. Their historical and present common uses however are documented by dictionaries et al. The most authoritative source on the term "black hat" is probably esr's jargon file: http://www.catb.org/jargon/html/B/black-hat.html To save the click: "1. [common among security specialists] A cracker, someone bent on breaking into the system you are protecting." Your (and hdyr's) looser ver…
This is exactly my point. The Jargon file is pretty dated and imo the definition given there isn't really adequate.
My looser version is indeed in common usage. If nothing else 5 HN users seem to agree with my definition enough to upvote my initial comment on the matter.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#219Earlier quoted context omitted.
Vulnerability and Exploit are different.
Can you demonstrate a vulnerability without producing an exploit? You have to provide a poc to demonstrate it to others at least, no? Two sides of the same coin
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#220Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…
And that's the creation date, not even when they were published.