Earlier quoted context omitted.
First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome
> Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
291–300 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#292Earlier quoted context omitted.
How do we know this guy's not a conspirator?
Track record of research/publications in the field? https://www.trailofbits.com/research-and-development/publish... Ian Cutress of Anandtech appears to be quasi-vouching for Dan Guido. Ian is also interviewing CTS Labs tomorrow morning, and looking for questions. https://twitter.com/IanCutress/status/973678700687450113 https://twitter.com/IanCutress/status/973697525071994880
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#293Earlier quoted context omitted.
> and then telling you about it? The argument against your position that people are trying to get across to you is not that. It is that publication of vulnerability without giving heads-up and time to prepare solution to the vendor greatly increases the risk that a user will be harmed by attackers exploiting the public knowledge. Often substantial number of users are not going to mitigate or resolve the problem witho…
And if I don't want to jump through whatever random hoops message board nerds have erected and just decide not to disclose at all, exactly how are you better off?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#294Earlier quoted context omitted.
I think saying that they were outdone by 4 dudes in a basement is being intellectually dishonest. There are a lot of dudes in a lot of basements looking for vulnerabilities all the time. Those four happened to find it, but there were hundreds of others looking. There’s no amount of money that amd can spend that would make them not outgunned eventually by all the hackers and intelligence services and security research…
Why do you assume that there were hundreds of other people looking for these vulnerabilities? Chances are, when we learn the technical details, we're going to find out that they're bog-standard memory corruption flaws in driver code, and that the thing that prevented anyone from discovering them was that nobody looked for them .
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#295Earlier quoted context omitted.
I even thought Meltdown/Spectre was overblown, and the average user will never see these attacks.
Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#296Earlier quoted context omitted.
Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.
They're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#297Earlier quoted context omitted.
Why do you assume that there were hundreds of other people looking for these vulnerabilities? Chances are, when we learn the technical details, we're going to find out that they're bog-standard memory corruption flaws in driver code, and that the thing that prevented anyone from discovering them was that nobody looked for them .
Have you ever worked with a code base before? Even when you scrutinize for bugs, they still can go unspotted. Sometimes hundreds of people can look at the same code and not see anything wrong with it. Software has the benefit of having higher levels of abstraction, I haven't designed any hardware but as far as I'm aware it's not easy to abstract it. That will make it much harder to find things. While 4 guys in a base…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#298Earlier quoted context omitted.
I think your perspective is a bit narrow. If you consider each individual person, [3] is indeed nonsense. However, the impact of many hacks comes disproportionally from high-value targets. Some high-value targets (e.g. key infrastructure, parts of government, major enterprises) have dedicated security teams, and can come up with a pretty decent response if given the appropriate information. Divulging vulnerability in…
Nobody appointed these security researchers to the authority to which you assign to their actions, though. Burning the immediate user on the off chance that it helps the hypothetical future user is some very weak tea. I agree that some proponents of immediate disclosure would claim that their actions encourage vendors to ship less vulnerable hardware or software. I do not believe that that, in the general case, is wh…
However, overall, I agree with you. Person with exploit needs to compare the probable consequences of disclosing at time N vs. disclosing at time N+1.
If it's being exploited in the wild and users can meaningfully self-protect, disclose now!
If the vendor will probably have a patch in 2 weeks, there is not widespread exploitation of the vulnerability, and disclosing now will cause widespread exploitation, disclose in 2 weeks.
If the vendor seems like they will never issue a patch on their own (because significant time has elapsed), such that at some point in the future there's going to be widespread exploitation and you're only hastening that a bit, go ahead and disclose now.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#299> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time. 90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional. Full, immediate disclosure is responsible.
And the users downstream of bugs that are made more widely vulnerable--because, as anyone who saw how, as an example, previously rare MitM attacks became commonplace after Firesheep etc. were publicized, obscurity is in fact a component of security --are...? Well, fuck 'em, I guess. Responsible disclosure, contrary to the super-cool leet kid notions expressed by people with who choose to exhibit an underdeveloped soc…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#300>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…
Interestingly, you'll note that the researchers claim public interest as their reason for non-standard practices, but then later it is revealed you need admin privileges to exploit them. The rhetoric the researchers use is inflammatory and staged in a media savvy way like a PR campaign.
This is a totally evidence free assertion and I'm not an infosec person (and am therefore happy to be set straight by experts) but I'll be happy to crack open the popcorn if something interesting is revealed a few years down the line.