Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

291–300 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#291

Earlier quoted context omitted.

First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome

> Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...

It was only disabled as a mitigation to these specific attacks, in case you though it was an experimental or “at your own risk” type of thing.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#292
post #282

Earlier quoted context omitted.

How do we know this guy's not a conspirator?

Track record of research/publications in the field? https://www.trailofbits.com/research-and-development/publish... Ian Cutress of Anandtech appears to be quasi-vouching for Dan Guido. Ian is also interviewing CTS Labs tomorrow morning, and looking for questions. https://twitter.com/IanCutress/status/973678700687450113 https://twitter.com/IanCutress/status/973697525071994880

[deleted]

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#293
post #257

Earlier quoted context omitted.

> and then telling you about it? The argument against your position that people are trying to get across to you is not that. It is that publication of vulnerability without giving heads-up and time to prepare solution to the vendor greatly increases the risk that a user will be harmed by attackers exploiting the public knowledge. Often substantial number of users are not going to mitigate or resolve the problem witho…

And if I don't want to jump through whatever random hoops message board nerds have erected and just decide not to disclose at all, exactly how are you better off?

From this and other similar responses of yours here I think that you do not have a convincing way to resolve the obvious problem with the absolutist 'i can do whatever i want with my research' stance that people here pointed out to you. So you do whataboutism directed at vendors, misrepresent people's arguments or try to pivot the discussion. Perhaps it is time to write less and let the discussion sink in a little. You may find a better way to argue your point, or even find you no longer want to do that.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#294

Earlier quoted context omitted.

I think saying that they were outdone by 4 dudes in a basement is being intellectually dishonest. There are a lot of dudes in a lot of basements looking for vulnerabilities all the time. Those four happened to find it, but there were hundreds of others looking. There’s no amount of money that amd can spend that would make them not outgunned eventually by all the hackers and intelligence services and security research…

Why do you assume that there were hundreds of other people looking for these vulnerabilities? Chances are, when we learn the technical details, we're going to find out that they're bog-standard memory corruption flaws in driver code, and that the thing that prevented anyone from discovering them was that nobody looked for them .

Have you ever worked with a code base before? Even when you scrutinize for bugs, they still can go unspotted. Sometimes hundreds of people can look at the same code and not see anything wrong with it. Software has the benefit of having higher levels of abstraction, I haven't designed any hardware but as far as I'm aware it's not easy to abstract it. That will make it much harder to find things. While 4 guys in a basement may have found this vulnerability, it doesn't mean they will find every vulnerability or that anyone else would have this as they had. Throwing money at verification will not make it fool proof.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#295
post #209

Earlier quoted context omitted.

I even thought Meltdown/Spectre was overblown, and the average user will never see these attacks.

Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.

They're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#296
post #295

Earlier quoted context omitted.

Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.

They're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.

That's true because the vulnerability itself wasn't overblown, and was immediately patched.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#297

Earlier quoted context omitted.

Why do you assume that there were hundreds of other people looking for these vulnerabilities? Chances are, when we learn the technical details, we're going to find out that they're bog-standard memory corruption flaws in driver code, and that the thing that prevented anyone from discovering them was that nobody looked for them .

Have you ever worked with a code base before? Even when you scrutinize for bugs, they still can go unspotted. Sometimes hundreds of people can look at the same code and not see anything wrong with it. Software has the benefit of having higher levels of abstraction, I haven't designed any hardware but as far as I'm aware it's not easy to abstract it. That will make it much harder to find things. While 4 guys in a base…

I've been a professional software developer since 1995.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#298

Earlier quoted context omitted.

I think your perspective is a bit narrow. If you consider each individual person, [3] is indeed nonsense. However, the impact of many hacks comes disproportionally from high-value targets. Some high-value targets (e.g. key infrastructure, parts of government, major enterprises) have dedicated security teams, and can come up with a pretty decent response if given the appropriate information. Divulging vulnerability in…

Nobody appointed these security researchers to the authority to which you assign to their actions, though. Burning the immediate user on the off chance that it helps the hypothetical future user is some very weak tea. I agree that some proponents of immediate disclosure would claim that their actions encourage vendors to ship less vulnerable hardware or software. I do not believe that that, in the general case, is wh…

Well, the very idea that there is some timelimit on mitigation before the flaw is disclosed anyways is that "very weak tea".

However, overall, I agree with you. Person with exploit needs to compare the probable consequences of disclosing at time N vs. disclosing at time N+1.

If it's being exploited in the wild and users can meaningfully self-protect, disclose now!

If the vendor will probably have a patch in 2 weeks, there is not widespread exploitation of the vulnerability, and disclosing now will cause widespread exploitation, disclose in 2 weeks.

If the vendor seems like they will never issue a patch on their own (because significant time has elapsed), such that at some point in the future there's going to be widespread exploitation and you're only hastening that a bit, go ahead and disclose now.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#299
post #19
post #5

> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time. 90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional. Full, immediate disclosure is responsible.

And the users downstream of bugs that are made more widely vulnerable--because, as anyone who saw how, as an example, previously rare MitM attacks became commonplace after Firesheep etc. were publicized, obscurity is in fact a component of security --are...? Well, fuck 'em, I guess. Responsible disclosure, contrary to the super-cool leet kid notions expressed by people with who choose to exhibit an underdeveloped soc…

It is neither the vendor nor the researcher’s place to make those sorts of decisions on behalf of the end user, while keeping the end user ignorant of the fact that such a decision has been made for them.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#300
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

I'm not saying it was them, but I wouldn't be surprised if Intel was trying to recover its reputational damage by hiring ppl to heavily research breaks in AMD chips to even the reputational playing field. They're the ones that stand to gain the most from this legal but shady tactic and have been reportedly scared of losing their long held market dominance in desktops and servers. Iirc AMD wasn't vulnerable to Meltdown which I speculate changed the market calculus in ways detrimental to Intel that both companies would be well aware of.

Interestingly, you'll note that the researchers claim public interest as their reason for non-standard practices, but then later it is revealed you need admin privileges to exploit them. The rhetoric the researchers use is inflammatory and staged in a media savvy way like a PR campaign.

This is a totally evidence free assertion and I'm not an infosec person (and am therefore happy to be set straight by experts) but I'll be happy to crack open the popcorn if something interesting is revealed a few years down the line.

Post reply on HN