Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

221–230 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#221
post #204

Earlier quoted context omitted.

> These vulnerabilities are all post-compromise privilege escalation flaws I would say they are all invasive evil maid threat vectors. Each one requires either physical access to the hardware or (as you stated) an already established root privileges. We all know that if you have physical access to hardware, it's essentially game over. However . One of the vulnerabilities supposedly allowed to subvert UEFI secure boot…

While I'm fine with criticizing them for partial disclosure, I again have a problem mapping any of this back to ethics, because, again, independent researchers do not have an obligation to vendors or to any amorphous public. As long as they aren't literally exploiting (or arranging to have exploited) vulnerabilities to break into people's computers, or lying about what they found, I don't think ethics have much to sa…

No obligation to vendors, no obligation to the public, so what are your ethical standards exactly? It sounds like committing crimes is it, but that’s a legal standard and not an ethical one. At what point are you less of a researcher and more of a sociopath with a keyboard? What makes researching software vulnerabilities such a uniquely non-ethical undertaking compared to all other forms of research?

You seem like a living argument for ethical standards being imposed on your industry, by law if needed.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#222
Since all of this seems to be related to "Secure Boot" and other DRM related crap, can we please just have the option of booting with minimal firmware support, no hidden code, and go for a completely open, community maintained, and audit-able by /anyone/ infrastructure?

No, I don't want HDCP or any similar crap; let me run my servers and desktops in secure mode.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#223

Legal question: Insider trading claims might be difficult since you can claim the vulnerabilities were public knowledge waiting to be discovered, but... Can you trade on knowing the security disclosure timeline prior to your publication of the vulnerability? That would seem to be insider knowledge until AMD authorizes publication. E.g. I've got knowledge that AMD likely wouldn't be able to fix the flaws prior to my d…

> until AMD authorizes publication

AMD doesn't have the power to prevent publication of research from third party researchers that haven't entered in an agreement with them. This definitely isn't insider trading.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#224

24 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.

One difference between security researchers and "exploit creators", which is a term I think you just made up, is that exploit creators presumably release exploits . Don't tell HD Moore or the Metapsloit team about this, though. They may cry themselves to sleep tonight.

Creation and release are two different things. They have created the exploits, or else AMD wouldn't be taking them seriously. They have also contributed more to the re-creation of those exploits by others than they have to security. So you can quibble over whether others use the exact jargon that you would have, but that doesn't change the underlying reality.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#225

24 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.

You don't have to speculate. They admit having financial interests in the actual text of their report.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#226
post #223

Legal question: Insider trading claims might be difficult since you can claim the vulnerabilities were public knowledge waiting to be discovered, but... Can you trade on knowing the security disclosure timeline prior to your publication of the vulnerability? That would seem to be insider knowledge until AMD authorizes publication. E.g. I've got knowledge that AMD likely wouldn't be able to fix the flaws prior to my d…

> until AMD authorizes publication AMD doesn't have the power to prevent publication of research from third party researchers that haven't entered in an agreement with them. This definitely isn't insider trading.

> AMD doesn't have the power to prevent publication of research from third party researchers that haven't entered in an agreement with them. This definitely isn't insider trading.

Correct, though this assumes AMD has yet to reply. If AMD did reply after the initial disclosure and before any trades were made, then the order of events which may warrant such a look would be:

- Private Disclosure made.

- AMD replies privately with anything substantive. This could include a timeline, or even an indication that a fix may take a while.

- Trades made.

- Public disclosure made.

Should events follow this sequence, trades made would have been informed by private knowledge from AMD that had yet to be released.

I'm not saying this is how it played out, but if it did, I'd suspect some amount of legal exposure.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#227
post #223

Earlier quoted context omitted.

> until AMD authorizes publication AMD doesn't have the power to prevent publication of research from third party researchers that haven't entered in an agreement with them. This definitely isn't insider trading.

> AMD doesn't have the power to prevent publication of research from third party researchers that haven't entered in an agreement with them. This definitely isn't insider trading. Correct, though this assumes AMD has yet to reply. If AMD did reply after the initial disclosure and before any trades were made, then the order of events which may warrant such a look would be: - Private Disclosure made. - AMD replies priv…

> AMD replies privately

Their replies are only private if the discloser keeps them private. The discloser is free to publish their correspondences with AMD which may include a timeline.

Regardless, this entire publication can happen without once talking to AMD. There is no need to notify or correspond with AMD in order to publish the security research and short AMD's stock.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#228
post #63

Earlier quoted context omitted.

Nice non-sequitur. Somehow the limiting factor on the ability of someone to judge professionalism is the number of papers they've written?

No, I'm just noticing again that people who don't don't do a lot of vulnerability research have a lot of interesting opinions about the professional norms of people who do that work. But you never know --- maybe they do a lot of research, in which case, yes, their opinion on security research norms is a lot more interesting to me.

Matasano and you got owned quite frequently back in the day. Should be judge you or your company or your opinions based on that too?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#229
post #140

Earlier quoted context omitted.

More and more lately I'm leaning towards the, "responsible disclosure is a bunch of crap" camp. You have to be "in" to get the news. Even if you're "in" security people love to play info war power games and withhold things because it tickles their jimmies, etc. And don't forget, you're deliberately keeping a vulnerability secret from consumers during a long period where you have no idea who else knows about it. If I'…

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…

It looks like the short notice in this case is not intended to force a timely fix, but to prevent it. They are hoping to cause as much of damage to the company as possible both directly and indirectly through its customers so they can profiteer from it.

I'd say that the intent makes this qualitatively different to what I'd consider legitimate disclosure.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#230
post #227

Earlier quoted context omitted.

> AMD doesn't have the power to prevent publication of research from third party researchers that haven't entered in an agreement with them. This definitely isn't insider trading. Correct, though this assumes AMD has yet to reply. If AMD did reply after the initial disclosure and before any trades were made, then the order of events which may warrant such a look would be: - Private Disclosure made. - AMD replies priv…

> AMD replies privately Their replies are only private if the discloser keeps them private. The discloser is free to publish their correspondences with AMD which may include a timeline. Regardless, this entire publication can happen without once talking to AMD. There is no need to notify or correspond with AMD in order to publish the security research and short AMD's stock.

> Their replies are only private if the discloser keeps them private. The discloser is free to publish their correspondences with AMD which may include a timeline.

Sure, but if trades are made and correspondences are subsequently released, those trades were made with insider information is my point.

Post reply on HN