Earlier quoted context omitted.
If I were a researcher, I'd be happy to delay for 6 months for a reward Really? What if a nation state actor has discovered the same bug. Do you want to keep the world vulnerable for a 6 month window? Also, most European university researchers are funded through taxpayer money. They should do what is best for the general population, not what is best of some company's stock value.
> most European university researchers are funded through taxpayer money This is absolutely not a given. While it might be partially true, they are frequently also funded through corporate grants.
Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
11–19 of 19 posts
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#12Is this a bribe? A bug bounty is a standard program for lots of companies, we don't consider the bounty a bribe. I mean, you could bribe someone in this way but there needs to be some nefarious intent going on - just giving them money to delay announcement until you've fixed the bug seems like a fairly pure motive to me.
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#13Is this a bribe? A bug bounty is a standard program for lots of companies, we don't consider the bounty a bribe. I mean, you could bribe someone in this way but there needs to be some nefarious intent going on - just giving them money to delay announcement until you've fixed the bug seems like a fairly pure motive to me.
Why would companies pay a bug bounty and then expect nothing in return?
In the case of bug bounties, one self-interested reason for them is to provide an alternative to the black market in vulnerabilities.
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#14Earlier quoted context omitted.
> most European university researchers are funded through taxpayer money This is absolutely not a given. While it might be partially true, they are frequently also funded through corporate grants.
The only European country where I'm somewhat familiar with research funding is Sweden and at least there direct corporate funding is a tiny sliver of the overall university research budget. And even when companies do fund research projects much of the funding is things like letting their researchers work 'for free' on the project or giving free access to data, equipment and licenses rather than cash
It's interesting to see that policies differ so much even inside of the relatively wealthy parts of Europe :)
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#15Earlier quoted context omitted.
The only European country where I'm somewhat familiar with research funding is Sweden and at least there direct corporate funding is a tiny sliver of the overall university research budget. And even when companies do fund research projects much of the funding is things like letting their researchers work 'for free' on the project or giving free access to data, equipment and licenses rather than cash
I only really know two northwestern (European) countries and they are both not Sweden. Corporate funding there is "strings attached" money, both for direction and scope of the research (and in at least one case a final say on whether or not research gets published). Corporate funding is also somewhat expected, as working from just government money is a huge outlier (it is not enough). It's interesting to see that pol…
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#16Is this a bribe? A bug bounty is a standard program for lots of companies, we don't consider the bounty a bribe. I mean, you could bribe someone in this way but there needs to be some nefarious intent going on - just giving them money to delay announcement until you've fixed the bug seems like a fairly pure motive to me.
They offered them a lower bug bounty reward with a big "gift" on the side. This would mean Intel gets to report the bug as lower severity. And presumably the extra "gift" money, which raises the total paid above the max bounty they normally offer by $20,000, had some strings attached. I've already read articles that some of the vulnerabilities were found more than a year ago. And as others reported similar exploits,…
When the impact is new microcode for every out-of-order CPU going back to Sandy Bridge that's not on its face entirely unreasonable. The date for the new microcode for my Ivy Bridge workstation I'm typing this on is 2019-02-13; if testing followed that.... Could even be they wanted to further delay release until they could do more testing.
> They had enough time to fix and release new silicon!
And properly test it?
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#17Earlier quoted context omitted.
I think it depends on if the agreement is to delay the announcement, or hide the announcement forever. If I were a researcher, I'd be happy to delay for 6 months for a reward, but I would consider it morally bad to delay forever for a reward.
If I were a researcher, I'd be happy to delay for 6 months for a reward Really? What if a nation state actor has discovered the same bug. Do you want to keep the world vulnerable for a 6 month window? Also, most European university researchers are funded through taxpayer money. They should do what is best for the general population, not what is best of some company's stock value.
There exist far more bugs than discovered bugs. By revealing it, I put some people at risk (those who fail to update), and by hiding it I put more people at less risk (everyone, but only if someone else discovers the bug).
It's a tradeoff, but 6 months is a good window for most people to update, while there still not being too much chance of the bug being independently discovered.
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#18Earlier quoted context omitted.
I think it depends on if the agreement is to delay the announcement, or hide the announcement forever. If I were a researcher, I'd be happy to delay for 6 months for a reward, but I would consider it morally bad to delay forever for a reward.
It became morally bad to delay any longer once it was obvious that multiple teams were finding the same bugs. There's a crap ton of people listed as discoverers in the CVE's. Who knows how many other actors discovered the same bugs and didn't say anything? Likely multiple, honestly. We've finally run into a real life proof of why bug embargoes are bad. This is the first time I know of that multiple people independent…
Re: Intel offered “reward” to Dutch researchers to downplay MDS vulnerability
#19Earlier quoted context omitted.
It became morally bad to delay any longer once it was obvious that multiple teams were finding the same bugs. There's a crap ton of people listed as discoverers in the CVE's. Who knows how many other actors discovered the same bugs and didn't say anything? Likely multiple, honestly. We've finally run into a real life proof of why bug embargoes are bad. This is the first time I know of that multiple people independent…
Saying something is "morally bad" doesn't really make sense unless you also define the moral framework that it is bad in. As you did not do so, it reads as if you expect the reader to understand what morality it is bad in (maybe even that it is obvious).