Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

241–250 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#241
post #184

Linus' reaction: https://plus.google.com/+LinusTorvalds/posts/PeFp4zYWY46

It's quite unsettling that Linus thinks as much of security in general, given that he maintains a kernel and he's responsible for accepting its security modules that are next to unusable because of their complexity. Could his general disbelief lead to a (kind of) dismissive attitude in this respect? Keep in mind he's the one that would never properly disclose of a security fix - instead of saying which problem is fixed, the general approach is to just publish a new kernel minor release and say "some security bugs are fixed, go figure".

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#242

Wild guess / conspiracy theory: Intel, afraid of the damage to their image just made worse by diminished performance advantage compared to AMD )due to Meltdown), fearing long-term market loss, quickly found ways to tackle the issue by, instead of pedaling to regain trust, damaging a competitor's image. It seems like a reasonable long game to support and perhaps steer the disclosure of AMD vulnerabilities that CTS-lab…

My guess is that some researcher found something and decided to maximize profits, scraping the bottom of the barrel of quasi-vulnerabilities, creatively exaggerating, and bringing in the lawyers, the financiers and the PR weasels needed to throw a scary web site and a misleading "white paper" at AMD. We'll see what CTS works on next.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#243
post #76
post #38

Earlier quoted context omitted.

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…

> I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick

So are you talking about AMD being dicks by releasing buggy chips, or the researchers somehow being dicks for finding out?

Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the vendor 90 days notice before telling the public?

While I think it's reasonable and appropriate professional practice for _some people/teams_ to go down the "coordinated disclosure" path (I think the world is a better place for having Tavis Ormandy disclose the way he chooses to), it does without doubt benefit the company who's products are flawed more than the researcher or the public. Anybody who knows they work at a firm that's going to be described dismissively like AMD here did "This company was previously unknown to AMD" is quite likely correct to publish-and-be-damned, because you can bet there's a non-zero chance that AMD's response to non-public disclosure is going to include either stonewalling and stringing the problem out as long as possible, or lawyering up ad threatening to sue the "previously unknown to AMD" company into oblivion.

If you don't want public disclosure of security flaws about your products, either don't make flawed products or don't ship them to the public. Especially if some of the key selling features of said product include bullet points like "AMD Secure OS".

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#244
post #38

Earlier quoted context omitted.

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

3. The vulnerabilities are minor, barely worse than normal expected behaviour; just enough to call them vulnerabilities. All these "exploits" consist of using ultra-privileged access (signed device drivers, or flashing the BIOS) for bad purposes. In the white paper, many attacks are hypothetical and many phrases are vague and slippery, suggesting the "researchers" barely achieved execution of something, not real payl…

Pwn2own, iOS jailbreaking, and Playstation hacking have shown time and time again that chaining up seemingly innocuous exploits to get to the stage where you can run a "minor exploit which requires ultra-privileged access" is definitely within the reach of bored/smart teenagers with no more motivation than a new laptop or gaining the ability to pirate or cheat at games...

Suggesting this is "just hypothetical" because "nobody is going to get physical access or code execution in a signed driver" is pretty shortsighted in my opinion...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#245

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

Well, this could be interesting. AMD is a US listed security. If true, these two lads could very look forward to a visit from the US SEC. Seeing as how market manipulation is not a capital-crime, I don't see Australia objecting to an extradition, should charges be warranted.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#246
post #76

Earlier quoted context omitted.

People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…

> I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick So are you talking about AMD being dicks by releasing buggy chips, or the researchers somehow being dicks for finding out? Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the…

> about AMD being dicks by releasing buggy chips

Everybody releasing chips releases buggy chips. It's the current reality of both hardware and software. Unless they do it maliciously, they're not dicks.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#247
post #196
post #93

Earlier quoted context omitted.

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…

> you are a better person than that I don't think this is an appropriate way to argue. Sounds like if he disagrees with you, he is somehow below standard. > It's just...minimal decency, to care about other people. Alerting folks to the danger that they face is one way to do so. Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remov…

> Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remove themselves from harm.

That is true, but you missed the other side of the argument. Coordinated disclosure is preferable also to a part of users/customers. Significant part of them have no understanding or incentive enough to mitigate on their own. So the question the discoverer of a bug then faces is 'how much headstart should I give the vendor and the users that depend on the vendor, before I make this public'? This has no universal answer, it may depend on how long the bug is out there and what kind of users may be harmed. But it is easy to see that a little headstart in terms of weeks is more reasonable than headstart=0, especially for bugs that are out there for years.

> why not argue for Responsible Development? This is where the outcry should be. Flaws in products come about because they are shipped before they are finished.

Flaws are not always due to cutting corners. Some bugs in computers are very unintuitive and it could be years before they manifest. More responsible development seems like a good idea, but again, this ignores the other part of the problem - major group of users do not understand the intricacies of development and are not willing to buy more 'responsible' product, if it is 5years behind the newest trend and costs 5x as much.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#248
post #181

Earlier quoted context omitted.

> They do not make money from the exploitation of the companies whose software/hardware they find flaws in. Right, and neither did these researchers. In point of fact, no, the difference really isn't all that stark. It's a difference of degree, not category. You apparently have a problem with disclosing vulnerabilities without providing advanced notice to the vendor, and you consider it especially distasteful to do s…

>Right, and neither did these researchers. I'm just going to conclude that you are trolling at this point and try to forget this headache of a thread.

Actually dsacco convinced me with his arguments (that those guys are not black hats). Don't assume bad faith in opponents when you are losing the argument ...

On the other hand I agree with responsible disclosure. And I think that should be made mandatory by law.

And finally, I also agree with some fines for companies allowing these holes to exist for so long. Especially those discoverable by 4 (more or less) random guys.

This is not black and white situation, so don't look for easy conclusions.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#249
post #177

Earlier quoted context omitted.

There is far far more incentive for AMD and its partners to understate the severity.

I disagree. AMD needs to maintain it's reputation over time. Short sellers make their profit over a few hours/days and don't care if they are proven wrong. So, AMD has vastly more incentive to be accurate than short sellers.

Pity that vast incentive didn't seem to work out when they promoted all these chips as having "Firmware Trusted Platform Module", "Secure Encrypted Virtualization", "AMD Secure Processor", and "AMD Secure OS" as features.

AMDs incentive, like any corporation, is to maximise shareholder value. Same as any tiny little security research firm. If a research firm can maximise their profit buy discovering vulnerabilities and shorting stock before disclosing them, is that any ethically worse than a chip company rushing out flawed hardware with big flashy marketing bullet points claiming how secure they are?

(I'm not saying short-selling chip vendor stocks on the back of vulnerabilities is a way I'd choose to make a living, but surveillance capitalism doesn't seem an "ethically better" industry to work in either...)

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#250
post #247
post #196

Earlier quoted context omitted.

> you are a better person than that I don't think this is an appropriate way to argue. Sounds like if he disagrees with you, he is somehow below standard. > It's just...minimal decency, to care about other people. Alerting folks to the danger that they face is one way to do so. Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remov…

> Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remove themselves from harm. That is true, but you missed the other side of the argument. Coordinated disclosure is preferable also to a part of users/customers. Significant part of them have no understanding or incentive enough to mitigate on their own. So the question the discove…

What about the flaws that aren't unintuitive? What about the bog standard integer overflows vendors routinely leave in code because they won't pay what it costs to ensure they don't ship them?
Post reply on HN