Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

281–290 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#281
Apparently all these can only be exploited if you already have administrator privileges. Raymond Chen calls that "being on the other side of the airtight hatchway" and has written about it numerous times.

https://blogs.msdn.microsoft.com/oldnewthing/20060508-22/?p=...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#282
post #205

A security researcher claims to have access to the full (non-public) technical report as well as PoC exploits for it. He says they're legit, and they are flaws, not just "you can do admin things with an admin password". https://twitter.com/dguido/status/973628511515750400 Sounds like the capabilities include the ability to jump outside a VM sandbox, take over the PSP, and pivot to the firmware or BIOS exploits. https…

How do we know this guy's not a conspirator?

Track record of research/publications in the field?

https://www.trailofbits.com/research-and-development/publish...

Ian Cutress of Anandtech appears to be quasi-vouching for Dan Guido. Ian is also interviewing CTS Labs tomorrow morning, and looking for questions.

https://twitter.com/IanCutress/status/973678700687450113

https://twitter.com/IanCutress/status/973697525071994880

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#283

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

If they did this just to short AMD and make money, that's indeed quite shady, and they go through all the trouble of hiding their real intentions because they also know it's super-shady.

That said, unless the whole "research" is fake, I wonder if we could be seeing more such tactics in the future against tech companies, and whether or not that would give them an immense incentive to care about security - or risk getting ruined in the stock market.

Honestly, such a huge incentive may actually be needed to get most companies to get about security. The money equation needs to make sense to them. Right now most think investing the absolute minim amount in security for compliance reasons is already too much money wasted on security. If this were to become common, I think maximizing security would actually start looking quite profitable to them.

I mean, this research is already saying there are some backdoors in AMD's chips. I imagine in the future, companies would be way more careful about allowing backdoors in their products, whether intentionally or by mistake, if they knew they risked getting their stock crushed.

So yeah I just like to play with this idea a little bit. So far this revelation doesn't seem to have had the "desired" effect by the backers of the research, though, but we'll see. I just want to know whether or not the research is real, so I'll wait for AMD's confirmation. I assume AMD wouldn't try to lie to us about it, because there are now probably at least a dozen security teams trying to pick AMD's chips apart, so the flaws would be found soon enough, if real.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#284

Legal question: Insider trading claims might be difficult since you can claim the vulnerabilities were public knowledge waiting to be discovered, but... Can you trade on knowing the security disclosure timeline prior to your publication of the vulnerability? That would seem to be insider knowledge until AMD authorizes publication. E.g. I've got knowledge that AMD likely wouldn't be able to fix the flaws prior to my d…

Insider trading usually implies coming into possession of confidential information and acting on it. Trading on non-public information that results from your own research and then announcing it is not illegal. Imagine someone buying stock and then saying the company is good. Not very controversial is it. Warren Buffet does it. Shorting stock and saying the company is bad is just the flip side of it. In fact, there ar…

> Trading on non-public information that results from your own research and then announcing it is not illegal.

Correct. I'm not referring to this. I'm referring to trading on information discerned from communications with e.g. AMD but prior to disclosure of the vulnerability, especially if those communications which establish e.g. timelines are only disclosed after trading

Hence my point about trading upon understanding AMD's response timeline e.g. from emailing them.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#285
post #254

Earlier quoted context omitted.

Pity that vast incentive didn't seem to work out when they promoted all these chips as having "Firmware Trusted Platform Module", "Secure Encrypted Virtualization", "AMD Secure Processor", and "AMD Secure OS" as features. AMDs incentive, like any corporation, is to maximise shareholder value. Same as any tiny little security research firm. If a research firm can maximise their profit buy discovering vulnerabilities a…

CPU's have real value. As to ethics that's mostly irrelevant to this discussion. Both sides could have ethical behavior, I am simply pointing out which side has the larger incentives to exaggerate. After all the stock could drop and a short seller could still lose money. They need the stock to drop a lot even over a minor issue.

I'd argue that vulnerability research has real value as well.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#287

Earlier quoted context omitted.

Just look at what Citron Research did to Shopify last year. They tanked the stock from $120 to $93 just based on false accusations that they put out in a "report". Now Shopify is now closer to $150...so their plan worked.

> just based on false accusations that they put out in a "report". If it's false information, isn't that classic stock manipulation? I thought for it to be legal to make money on the stock it had to be both accurate and publicly available (if potentially hard to put together)?

They make claims that are demonstrably...stupid. I don't know if there's a better, more nuanced word to use here. It's trolling in broad daylight from what I can tell.

Watch the video and see for yourself: http://citronresearch.com/citron-exposes-the-dark-side-of-sh...

That video by itself tanked the stock for many many weeks, until they finally reported quarterly results and it started climbing again.

I'm glad the CEO didn't feed the trolls by acknowledging this report in any depth.

Also shows how irrational the stock market is in the short term.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#288
This has all the signs of a bonafide smear job, Intel has a huge presence in Israel, lot's of investments there.

Wouldn't take much to use stealth proxy operatives to carry out such a smear, and guess who benefits the most from a smear of AMD ?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#289
post #91
post #77

Earlier quoted context omitted.

What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html

Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...

Seriously, if some fly-by-night security outfit has managed to discover this, they're probably not the only ones.

They didn't blow full technical details on this exploit after 24 hours, they went public with a summary... one that's so high-level that many people are even doubting they exist. That's not exactly dumping a zero-day on the internet either.

There's a whole lot of shooting-the-messenger going on with this topic. Making plays against the stock is scummy and possibly illegal, but that doesn't make the exploits here any less real (assuming they are). These are actually quite serious breaks, potentially VMs can jump the sandbox straight into SMM mode and PSP, so it actually is much more severe than just "root password lets you do root things".

https://twitter.com/c7zero/status/973668616183754753

There is a long and storied history of showing the disadvantages of your competitor's products. Edison went on a campaign against Westinghouse's AC electricity, culminating in him electrocuting an elephant to death to demonstrate how dangerous it is.

Right now we need more spotlights on computer security than ever, and as long as it gets bugs patched (hardware, software, or firmware) I don't really care who's doing it or what their short-run motivations are. If AMD won't secure their code appropriately and Intel wants to call them out, fine. If Intel is leaking timings through sidechannels and AMD wants to call them out on it, fine.

And if we want to throw stones here, it was AMD who blew the embargo on Meltdown a week early because they wanted to force a response from Intel at CES... different in degree, not really in kind.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#290
post #157

This is FUD. The original post was flagged, because the domain and website are far from trustworthy. Technically, the accusations seem to be more of a joke. Hello, Intel?

Dan Guido is backing up their claims.

How much money did Dan accept under the table, eh ?
Post reply on HN