Earlier quoted context omitted.
Can you point to a javascript example? I can think of a number of approaches, but nothing I could catergorise as trivial.
First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
271–280 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#272Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#273Earlier quoted context omitted.
First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome
> Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#274Earlier quoted context omitted.
I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…
”The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws.” I know everyone in my family is ignorant of this “disclosed” security flaw and is powerless to mitigate the vulnerabilities disclosed on their own. Even if they did know to “turn off their computer” as someone said, are they supposed to wait until someone calls them to tell them a patch…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#275A security researcher claims to have access to the full (non-public) technical report as well as PoC exploits for it. He says they're legit, and they are flaws, not just "you can do admin things with an admin password". https://twitter.com/dguido/status/973628511515750400 Sounds like the capabilities include the ability to jump outside a VM sandbox, take over the PSP, and pivot to the firmware or BIOS exploits. https…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#276Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#277Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…
https://finance.google.com/finance?q=amd
AMD $11.64Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#278Earlier quoted context omitted.
No obligation to vendors, no obligation to the public, so what are your ethical standards exactly? It sounds like committing crimes is it, but that’s a legal standard and not an ethical one. At what point are you less of a researcher and more of a sociopath with a keyboard? What makes researching software vulnerabilities such a uniquely non-ethical undertaking compared to all other forms of research? You seem like a…
In exactly what way are you harmed by someone discovering a vulnerability --- that existed whether or not they did the work --- and then telling you about it ? You're arguing that the force of law should prevent you from learning inconvenient things about the software you use.
You are harmed by them discovering a vulnerability and telling the world about it.
And if they discover a vulnerability and tell both you and the rest of the world, the harm may easily outweigh the benefit.
Suppose I go wandering around the city where you live, checking for unlocked house doors. I find that you've left your front door unlocked and gone on holiday. I then wander the streets shouting "Thomas's house is unlocked and no one's at home!". I also phone you up to let you know your house is unlocked.
It was your fault, not mine, that the house was unlocked and no one at home to deter burglars. In principle, anyone else could have come along and burgled your house, if they'd found it before I did. None the less, I think that in this scenario I have done you wrong.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#279Physical damage to hardware (SPI flash wear-out, etc.)
Reminds me of little kids trying to fill out their 200-word essays.