Earlier quoted context omitted.
> Could something like this be considered inside information? No, illegal insider trading refers to trading on inside information when you have a confidentiality agreement or a fiduciary duty. Information asymmetry is insufficient (or else it would be virtually impossible to profitably trade at all). > Or is it legal to actively manipulate stock prices to ones benefit in this way? The way you're presenting this is a…
Might the latter also depend on how you present it? As far as I can see this is only an exploit of secure boot if you are already on ring 0 level auth. Making a whole webpage with lots of graphics and whatnot, sending press releases all over and in general present it like a security flaw on the level of meltdown seems .. false? Probably court level material.. In any case it seems to have backfired as the stock is up.
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
131–140 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#132Insider trading claims might be difficult since you can claim the vulnerabilities were public knowledge waiting to be discovered, but...
Can you trade on knowing the security disclosure timeline prior to your publication of the vulnerability? That would seem to be insider knowledge until AMD authorizes publication. E.g. I've got knowledge that AMD likely wouldn't be able to fix the flaws prior to my disclosure. That knowledge would inherently be non-public.
Thoughts?
Disclosure: I've been long AMD for a while.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#133Earlier quoted context omitted.
I agree on the premise of moving the market but they don't necessarily need to be only short sellers, they could have hedged both ways and still made money. They could have exercised puts if it went down (which it did in the morning) or bought stock/calls both before the site release and in the case of it going down because they knew it wouldn't be a concern or dispelled by AMD. Unless, this is truly a flaw and in th…
What if I told you you can lose money on straddles and bear spreads.
Also, as nothing has been verified about the report (from AMD), there is still the potential for this to move either way.
Great username BTW
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#134Earlier quoted context omitted.
No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.
No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.
In any case, if we go by what you're saying, then anyone can define "black hat" to mean whatever they want, which means it's a meaningless and unproductive concept to throw around in conversation.
Your assertion is in a catch-22 here. Words have meaning without requiring an independent body to rigorously define them. The established definition of a black hat is someone who compromises other people using security failures for their own gain. If instead we choose to say that the term has no established definition, then the entire point is moot, because calling someone a "black hat" no longer means anything.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#135Earlier quoted context omitted.
I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…
This is probably where we diverge. From where I stand, "end users" are incapable of making a meaningful decision about security at this level. It would be awesome if they weren't, and god knows I have spent a decent amount of time in my life trying to bootstrap people into such a position, but it doesn't...like...work. There is a computing priesthood, as much as we have tried to democratize this stuff, and it's all g…
I don't see how you get there from here.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#136Earlier quoted context omitted.
These guys are essentially more black hat than white hat
No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.
ideological discussions about disclosure policy aside, if they are doing this to manipulate stock prices and in doing so create a situation where more actual exploits occur, I'd say that is 'black hat' behavior.. the 'weaponization' is in the 'social engineering' of the market reaction, rather than a direct exploit in this case..
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#137Earlier quoted context omitted.
People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…
Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.
That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#138Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#139https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#140Earlier quoted context omitted.
Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.
This is the crux of it. The short disclosure window could hurt 3rd parties unnecessarily. Although I enjoy reading grandparent's counterpoint