Earlier quoted context omitted.
> I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick So are you talking about AMD being dicks by releasing buggy chips, or the researchers somehow being dicks for finding out? Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the…
> about AMD being dicks by releasing buggy chips Everybody releasing chips releases buggy chips. It's the current reality of both hardware and software. Unless they do it maliciously, they're not dicks.
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
251–260 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#252Earlier quoted context omitted.
No, I'm just noticing again that people who don't don't do a lot of vulnerability research have a lot of interesting opinions about the professional norms of people who do that work. But you never know --- maybe they do a lot of research, in which case, yes, their opinion on security research norms is a lot more interesting to me.
Matasano and you got owned quite frequently back in the day. Should be judge you or your company or your opinions based on that too?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#253Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…
I even thought Meltdown/Spectre was overblown, and the average user will never see these attacks.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#254Earlier quoted context omitted.
I disagree. AMD needs to maintain it's reputation over time. Short sellers make their profit over a few hours/days and don't care if they are proven wrong. So, AMD has vastly more incentive to be accurate than short sellers.
Pity that vast incentive didn't seem to work out when they promoted all these chips as having "Firmware Trusted Platform Module", "Secure Encrypted Virtualization", "AMD Secure Processor", and "AMD Secure OS" as features. AMDs incentive, like any corporation, is to maximise shareholder value. Same as any tiny little security research firm. If a research firm can maximise their profit buy discovering vulnerabilities a…
As to ethics that's mostly irrelevant to this discussion. Both sides could have ethical behavior, I am simply pointing out which side has the larger incentives to exaggerate. After all the stock could drop and a short seller could still lose money. They need the stock to drop a lot even over a minor issue.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#255Earlier quoted context omitted.
This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…
It looks like the short notice in this case is not intended to force a timely fix, but to prevent it. They are hoping to cause as much of damage to the company as possible both directly and indirectly through its customers so they can profiteer from it. I'd say that the intent makes this qualitatively different to what I'd consider legitimate disclosure.
It's not like their marketing copy makes accurate claims like:
"We're reasonably sure our Firmware Trusted Platform Module is trustworthy, but we ran out of time to pentest it properly before we shipped it."
or
"Ryzen features Probably-Secure Encrypted Virtualization! Our interns couldn't break it in a afternoon of trying! The data looks random enough to us..."
How much does "the intent" of their marketing copy and claims come into play?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#256Earlier quoted context omitted.
I even thought Meltdown/Spectre was overblown, and the average user will never see these attacks.
Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.
I can think of a number of approaches, but nothing I could catergorise as trivial.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#257Earlier quoted context omitted.
No obligation to vendors, no obligation to the public, so what are your ethical standards exactly? It sounds like committing crimes is it, but that’s a legal standard and not an ethical one. At what point are you less of a researcher and more of a sociopath with a keyboard? What makes researching software vulnerabilities such a uniquely non-ethical undertaking compared to all other forms of research? You seem like a…
In exactly what way are you harmed by someone discovering a vulnerability --- that existed whether or not they did the work --- and then telling you about it ? You're arguing that the force of law should prevent you from learning inconvenient things about the software you use.
The argument against your position that people are trying to get across to you is not that. It is that publication of vulnerability without giving heads-up and time to prepare solution to the vendor greatly increases the risk that a user will be harmed by attackers exploiting the public knowledge. Often substantial number of users are not going to mitigate or resolve the problem without their vendor giving out the official solution.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#258Earlier quoted context omitted.
This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…
I agree, but I am curious if you have any suggestions on how we should be handling disclosure?
It's not like AMD set their chip prices based on "ethics" or "duty to the public". As "the public" I'd prefer a Ryzen 1900X to sell for $150 rather than $500 - It's just a bunch of sand after all (plus some intellectual effort). I don't think AMD get to choose their pricing model but then complain about how security companies price/sell their intellectual work...
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#259Earlier quoted context omitted.
> about AMD being dicks by releasing buggy chips Everybody releasing chips releases buggy chips. It's the current reality of both hardware and software. Unless they do it maliciously, they're not dicks.
Does everyone who releases drivers release buggy drivers?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#260Earlier quoted context omitted.
Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.
It's not their problem. There's no obligation for them to give any warning at all. They can just go public, short the stock, and watch it fall. The warning is just a polite thing to do
Do you think there's _any_ chance AMD would have offered these guys money in the sort of magnitude they stand to gain short selling AMD?
I'm pretty sure if they'd asked AMD would have responded with a blackmail lawsuit instantly.