Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
101–110 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#102Earlier quoted context omitted.
This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.
A new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices…
Now Shopify is now closer to $150...so their plan worked.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#103https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"
This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.
This is legit, and they haven't published anything that can be used maliciously.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#104Earlier quoted context omitted.
You can consult the search bar at the bottom of the page to learn that I am 100% OK with immediate, uncoordinated disclosure. It's not what I personally do, but that's easy for me to say because I don't find these kinds of vulnerabilities. This isn't "shoot the hostages". The researchers didn't manufacture the vulnerabilities; AMD did. If 4 dudes in a basement can find exploitable driver vulnerabilities, so can 10 re…
I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…
The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws.
No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation for any vulnerability: the power switch.
Most of the time, most users have better non-patching mitigations than that. These vulnerabilities are all post-compromise privilege escalation flaws. Their exploitation is situational and most users can do things to eliminate the situation that enables their exploit.
You might not like the fact that end-users have to make hard, expensive choices about how to mitigate flaws. But if you think about it for just a second, you'll see that the idea that patches were saving them from this choice was fallacious. There is no reason to believe these 4 dudes were the only ones in the world capable of finding these flaws (the reality is that if they're the only ones who know about them, it's because the kinds of flaws they found simply aren't important enough to demand focused attention from others). All restricted disclosure does is prevent end users from making the choice for themselves.
I believe that as a general rule, we're better off when we have the most information available to us about vulnerabilities. Personally, I'd probably stop short of publishing exploit code. But other researchers that most of us respect a great deal in the abstract do not have that particular scruple, and some --- like the original Metasploit project --- made it a point to publish exploit code immediately, patch or no patch, to arm operators with information about their exposure.
This isn't an idle opinion. If there was working Usenet search in 2018, you could find me making approximately the same argument back in the 1990s, when I worked as a researcher at SNI, the world's first commercial vulnerability research lab.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#105Earlier quoted context omitted.
What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html
Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...
Do you know that the general public are usually the ultimate victims and impacted by those vulnerabilities the most?
Especially Intel/AMD are corporations worth tens of billions monopolies in their fields, and if their CPUs with zero days unpatched and sample code and exploitation techniques out in the wild, what else are you gonna use on your desktop computers?
We've seen similar happened for Microsoft after Shadow Brokers's disclosure.[1] It's gonna be worse for hardware products as it's virtually impossible to retroactively fix silicons chips.
[1]: https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-...
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#106https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"
These guys are essentially more black hat than white hat
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#107Earlier quoted context omitted.
This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.
I can vet the guys who published this. This is legit, and they haven't published anything that can be used maliciously.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#108Earlier quoted context omitted.
These guys are essentially more black hat than white hat
No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#109Earlier quoted context omitted.
These guys are essentially more black hat than white hat
No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#110Earlier quoted context omitted.
Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...
So you believer in the absolute freedom of security vulnerabilities disclosures and security researchers should just do so at will? Do you know that the general public are usually the ultimate victims and impacted by those vulnerabilities the most? Especially Intel/AMD are corporations worth tens of billions monopolies in their fields, and if their CPUs with zero days unpatched and sample code and exploitation techni…