Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

121–130 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#121
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

From "Viceroy Research":

>We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries.

Direct quote from: https://viceroyresearch.files.wordpress.com/2018/03/amd-the-...

These guys are slimy as hell, this is disgusting.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#122
post #106

Earlier quoted context omitted.

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

Black hat isn't distinguished by failing to report vunlerabilities. It's distinguished by bad faith.

No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#123
post #114

Earlier quoted context omitted.

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

This is the crux of it. The short disclosure window could hurt 3rd parties unnecessarily.

Although I enjoy reading grandparent's counterpoint

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#124
post #122

Earlier quoted context omitted.

Black hat isn't distinguished by failing to report vunlerabilities. It's distinguished by bad faith.

No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.

No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#125
post #97

Earlier quoted context omitted.

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

I agree on the premise of moving the market but they don't necessarily need to be only short sellers, they could have hedged both ways and still made money. They could have exercised puts if it went down (which it did in the morning) or bought stock/calls both before the site release and in the case of it going down because they knew it wouldn't be a concern or dispelled by AMD. Unless, this is truly a flaw and in th…

What if I told you you can lose money on straddles and bear spreads.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#126
The upside of this is that most of these vulns are ineffective after disabling AMD "Secure" Processor at boot which is now an option in most firmware. Without breaking manufactures firmware upgrade key you cannot execute the first one to toggle the settings.

The interesting one is against Promontory. It still requires VM host access to exploit so the impact is limited.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#127
post #70

Earlier quoted context omitted.

If you put 10 people who find and publish security vulnerabilities professionally in a room, I do not think you would secure agreement that this is a "clear breach of ethics". There are extremely well-known researchers who have made a point of not coordinating with vendors; vendors, historically, have been far more abusive than researchers.

But security researchers don't exist in a vacuum: they're part of larger society. If the security researcher subgroup has a code of ethics that diverges too far from the popular perception of what their code of ethics should be, I could see popular pressure to bring them into alignment (all the way up to using the legal system). I'm not saying the non-security researcher users on HN have an opinion representative of…

Public security researchers compete with state-sponsored research teams and organized crime syndicates. Both of the latter entities are better funded than even commercial vulnerability teams, and neither of the latter publish any vulnerability information. I have a hard time ever seeing public researchers as the bad guys in these stories.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#128
post #106

Earlier quoted context omitted.

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

I think some here believe that the weapon here is financial; to trade the stock.

I'm sure they believe that, but to be blunt, that changes the definition of "black hat" from "compromising people with security vulnerabilities" to "doing things I personally find unsavory when publicly disclosing security vulnerabilities."

If people want to bend over backwards to make an argument about the abstract way in which people are harmed by small disclosure windows, activist investing or information asymmetry in the market, they're free to do so. But none of those things qualifies as black hat behavior. Definitions require precision to be useful, and you throw all precision out the window if you decide to lump people with disclosure habits you dislike in with organized criminals stealing identities en masse.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#129
Wild guess / conspiracy theory: Intel, afraid of the damage to their image just made worse by diminished performance advantage compared to AMD )due to Meltdown), fearing long-term market loss, quickly found ways to tackle the issue by, instead of pedaling to regain trust, damaging a competitor's image. It seems like a reasonable long game to support and perhaps steer the disclosure of AMD vulnerabilities that CTS-labs had been investigating. Or maybe is was Intel investigating themselves, had some cards up their sleeves, but needed some other entity to do the public disclosure.

Other theories discussed here seem less far-fetched than the above, but in any case, it does smell funny.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#130
post #6

Did anyone verify any of these? The whole thing reeks.

Good question. They call the "MASTERKEY attack" that requires a reflashed BIOS "remotely exploitable" because on some systems, the BIOS can be flashed from the OS. They then speculate "On motherboards where re-flashing is not possible because it has been blocked, or because BIOS updates must be encapsulated and digitally signed by an OEM-specific digital signature, we suspect an attacker could occasionally still succeed in re-flashing the BIOS." Page 9 in the PDF.

I'm not a professional security researcher but this is looking pretty darn flimsy. I also don't see any proof of concept code anywhere -- the "whitepaper" seems to just claim these things exist with very little mention of how to exploit them. Compare against Meltdown/Spectre, which was highly technical and had lots of PoC code. This just says "Upload malware to the processor" without further comment.

I'm not saying they didn't find anything, but whatever they found, they've hardly disclosed it.

Post reply on HN