Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

131–140 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#131
post #112
post #74

Earlier quoted context omitted.

> Could something like this be considered inside information? No, illegal insider trading refers to trading on inside information when you have a confidentiality agreement or a fiduciary duty. Information asymmetry is insufficient (or else it would be virtually impossible to profitably trade at all). > Or is it legal to actively manipulate stock prices to ones benefit in this way? The way you're presenting this is a…

Might the latter also depend on how you present it? As far as I can see this is only an exploit of secure boot if you are already on ring 0 level auth. Making a whole webpage with lots of graphics and whatnot, sending press releases all over and in general present it like a security flaw on the level of meltdown seems .. false? Probably court level material.. In any case it seems to have backfired as the stock is up.

I think the difference in facts you're talking about is a difference of degree, not category. In other words, it's not plainly false, there certainly is a vulnerability, it's just perhaps exaggerated. I could see a case being brought against the researchers on those grounds, but I'd be really surprised if anything came of it.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#132
Legal question:

Insider trading claims might be difficult since you can claim the vulnerabilities were public knowledge waiting to be discovered, but...

Can you trade on knowing the security disclosure timeline prior to your publication of the vulnerability? That would seem to be insider knowledge until AMD authorizes publication. E.g. I've got knowledge that AMD likely wouldn't be able to fix the flaws prior to my disclosure. That knowledge would inherently be non-public.

Thoughts?

Disclosure: I've been long AMD for a while.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#133
post #97

Earlier quoted context omitted.

I agree on the premise of moving the market but they don't necessarily need to be only short sellers, they could have hedged both ways and still made money. They could have exercised puts if it went down (which it did in the morning) or bought stock/calls both before the site release and in the case of it going down because they knew it wouldn't be a concern or dispelled by AMD. Unless, this is truly a flaw and in th…

What if I told you you can lose money on straddles and bear spreads.

Agreed on the losing money part, in general, but in a stock as volatile as AMD, I feel like there is an opportunity for this type of action, may not be the case for others.

Also, as nothing has been verified about the report (from AMD), there is still the potential for this to move either way.

Great username BTW

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#134
post #122

Earlier quoted context omitted.

No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.

No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.

There is a reasonably accepted definition for what a "black hat" is. I don't particularly agree with conceptually bucketing people into black hats or white hats, but the paradigm has an existing meaning.

In any case, if we go by what you're saying, then anyone can define "black hat" to mean whatever they want, which means it's a meaningless and unproductive concept to throw around in conversation.

Your assertion is in a catch-22 here. Words have meaning without requiring an independent body to rigorously define them. The established definition of a black hat is someone who compromises other people using security failures for their own gain. If instead we choose to say that the term has no established definition, then the entire point is moot, because calling someone a "black hat" no longer means anything.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#135

Earlier quoted context omitted.

I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…

This is probably where we diverge. From where I stand, "end users" are incapable of making a meaningful decision about security at this level. It would be awesome if they weren't, and god knows I have spent a decent amount of time in my life trying to bootstrap people into such a position, but it doesn't...like...work. There is a computing priesthood, as much as we have tried to democratize this stuff, and it's all g…

So the 11 billion dollar vendor who shipped vulnerabilities in the first place gets to treat these problems as an externality, but 4 dudes in a basement who did a basic research project have to be restrained from speaking?

I don't see how you get there from here.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#136
post #106
post #98

Earlier quoted context omitted.

These guys are essentially more black hat than white hat

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

black hats use them for bad, white hats use them for good.

ideological discussions about disclosure policy aside, if they are doing this to manipulate stock prices and in doing so create a situation where more actual exploits occur, I'd say that is 'black hat' behavior.. the 'weaponization' is in the 'social engineering' of the market reaction, rather than a direct exploit in this case..

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#137
post #114

Earlier quoted context omitted.

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction.

That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#139
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

Almost always these types of security incidents and breaches NEVER move stock prices negatively because frankly they don't impact business. $AMD is currently trading up 3.5% as of writing this. :-)

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#140
post #123

Earlier quoted context omitted.

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

This is the crux of it. The short disclosure window could hurt 3rd parties unnecessarily. Although I enjoy reading grandparent's counterpoint

More and more lately I'm leaning towards the, "responsible disclosure is a bunch of crap" camp. You have to be "in" to get the news. Even if you're "in" security people love to play info war power games and withhold things because it tickles their jimmies, etc. And don't forget, you're deliberately keeping a vulnerability secret from consumers during a long period where you have no idea who else knows about it. If I'm a "user" or 3rd party and there's a critical vuln in some system I depend on, I want to know that I shouldn't use it or that I should take extra caution or whatever rather than being clueless in all in the name of the vendor's image.
Post reply on HN