Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

231–240 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#231

Legal question: Insider trading claims might be difficult since you can claim the vulnerabilities were public knowledge waiting to be discovered, but... Can you trade on knowing the security disclosure timeline prior to your publication of the vulnerability? That would seem to be insider knowledge until AMD authorizes publication. E.g. I've got knowledge that AMD likely wouldn't be able to fix the flaws prior to my d…

Insider trading usually implies coming into possession of confidential information and acting on it. Trading on non-public information that results from your own research and then announcing it is not illegal.

Imagine someone buying stock and then saying the company is good. Not very controversial is it. Warren Buffet does it. Shorting stock and saying the company is bad is just the flip side of it.

In fact, there are equity research companies that do specifically that (e.g. Muddy Waters). Whether that research holds water or not is for the market to determine (AMD is up on the day).

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#232
post #61
post #38

Earlier quoted context omitted.

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

Go fuck yourself. There are plenty of ways to be outraged by the actions of these "independent reseachers." How about 1. Irresponsible disclosure affecting end users. 2. Shady trading practices of their hedge fund CFO. Just to name 2. You are a fucking retard, and your obvious anti-AMD bias is showing.

We've banned this account. If you would like to post civilly and substantively you're welcome to email us at hn@ycombinator.com and we'll unban it if we believe you will.

https://news.ycombinator.com/newsguidelines.html

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#233
post #140

Earlier quoted context omitted.

More and more lately I'm leaning towards the, "responsible disclosure is a bunch of crap" camp. You have to be "in" to get the news. Even if you're "in" security people love to play info war power games and withhold things because it tickles their jimmies, etc. And don't forget, you're deliberately keeping a vulnerability secret from consumers during a long period where you have no idea who else knows about it. If I'…

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…

But what if we give the list a really cool name like gazorpazorp?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#234

Earlier quoted context omitted.

An eye for an eye works only until everyone is blind. You seem to have several deeply misguided premises. 1. We don't know ARM knowingly shipped these chips although they were vulnerable. Bugs happen. 2. Even if this was the case, an individual can show, and ought to, show decency and empathy towards others. 3. This last comment of yours is a straw man and I doubt you are incapable of seeing this. You parent's argume…

I don't think you understand the dynamics here. I don't think anyone knowingly shipped vulnerabilities. That's an impossibly low bar: all you have to do to "not know" is to not spend any money on security verification. The complaint here is that AMD was outdone on verification by 4 dudes in a basement.

I think saying that they were outdone by 4 dudes in a basement is being intellectually dishonest. There are a lot of dudes in a lot of basements looking for vulnerabilities all the time. Those four happened to find it, but there were hundreds of others looking. There’s no amount of money that amd can spend that would make them not outgunned eventually by all the hackers and intelligence services and security researches looking to break it.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#235

Earlier quoted context omitted.

One difference between security researchers and "exploit creators", which is a term I think you just made up, is that exploit creators presumably release exploits . Don't tell HD Moore or the Metapsloit team about this, though. They may cry themselves to sleep tonight.

Creation and release are two different things. They have created the exploits, or else AMD wouldn't be taking them seriously. They have also contributed more to the re-creation of those exploits by others than they have to security. So you can quibble over whether others use the exact jargon that you would have, but that doesn't change the underlying reality.

Every security researcher creates exploits, so I'm not really sure what the distinction you're trying to make is.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#236

Earlier quoted context omitted.

While I'm fine with criticizing them for partial disclosure, I again have a problem mapping any of this back to ethics, because, again, independent researchers do not have an obligation to vendors or to any amorphous public. As long as they aren't literally exploiting (or arranging to have exploited) vulnerabilities to break into people's computers, or lying about what they found, I don't think ethics have much to sa…

No obligation to vendors, no obligation to the public, so what are your ethical standards exactly? It sounds like committing crimes is it, but that’s a legal standard and not an ethical one. At what point are you less of a researcher and more of a sociopath with a keyboard? What makes researching software vulnerabilities such a uniquely non-ethical undertaking compared to all other forms of research? You seem like a…

In exactly what way are you harmed by someone discovering a vulnerability --- that existed whether or not they did the work --- and then telling you about it?

You're arguing that the force of law should prevent you from learning inconvenient things about the software you use.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#237
post #38
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

3. The vulnerabilities are minor, barely worse than normal expected behaviour; just enough to call them vulnerabilities. All these "exploits" consist of using ultra-privileged access (signed device drivers, or flashing the BIOS) for bad purposes.

In the white paper, many attacks are hypothetical and many phrases are vague and slippery, suggesting the "researchers" barely achieved execution of something, not real payloads.

I hope AMD invests the little money needed to fund this sort of PR campaign, er, research initiative, against Intel. The net result would be a greater awareness of the perils of "sponsored" science and of the poor state of PC security.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#238

Earlier quoted context omitted.

I don't think you understand the dynamics here. I don't think anyone knowingly shipped vulnerabilities. That's an impossibly low bar: all you have to do to "not know" is to not spend any money on security verification. The complaint here is that AMD was outdone on verification by 4 dudes in a basement.

I think saying that they were outdone by 4 dudes in a basement is being intellectually dishonest. There are a lot of dudes in a lot of basements looking for vulnerabilities all the time. Those four happened to find it, but there were hundreds of others looking. There’s no amount of money that amd can spend that would make them not outgunned eventually by all the hackers and intelligence services and security research…

Why do you assume that there were hundreds of other people looking for these vulnerabilities? Chances are, when we learn the technical details, we're going to find out that they're bog-standard memory corruption flaws in driver code, and that the thing that prevented anyone from discovering them was that nobody looked for them.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#239
post #38

Earlier quoted context omitted.

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

3. The vulnerabilities are minor, barely worse than normal expected behaviour; just enough to call them vulnerabilities. All these "exploits" consist of using ultra-privileged access (signed device drivers, or flashing the BIOS) for bad purposes. In the white paper, many attacks are hypothetical and many phrases are vague and slippery, suggesting the "researchers" barely achieved execution of something, not real payl…

You're recapitulating an argument that Arrigo Triulzi posted on Twitter based on his reading of the CPS-Labs white paper. The white paper doesn't include technical information about the flaws.

Dan Guido and Trail of Bits got to read the actual report, and vouched for them as real vulnerabilities. The fact that there are vulnerabilities in signed drivers is a bad thing: it means that AMD shipped cryptographically signed versions of vulnerabilities. Arrigo's twitter thread implied that the use of signed code somehow mitigated the vulnerabilities, but the opposite thing is true.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#240
post #59

Earlier quoted context omitted.

Perhaps this is my ignorance, but I was under the impression that security disclosures are usually tightly coordinated to minimize exposure of innocent users. > "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before. Could you point me to an example of a zero warning disclosure that exposed a large amount of users without first attempting to coordinate with the responsible party?

Some researchers coordinate, some researchers don't. For a project originally organized around the principle of getting not just research results but functioning exploit code deployed regardless of vendor preparedness, look no further than Metasploit.

Wait, Metasploit of all things? They have been doing coordinated disclosure since forever.
Post reply on HN