Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

141–150 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#141
post #114

Earlier quoted context omitted.

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

> Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

A good way for companies to prevent this is to have a generous bug bounty program. Money is still transferred from the shareholders to the researchers, but then the company can impose conditions like delaying public disclosure for a reasonable time to prepare a fix.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#142
post #120
post #106

Earlier quoted context omitted.

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

If the term is flexible, why the hard reaction to my flexing of it? I agree with the sibling commenters here. This is a bad faith, financially-motivated disclosure with insufficient time given to AMD to react

> If the term is flexible, why the hard reaction to my flexing of it?

The terminology is not flexible, it has a well established meaning. If your bar for a black hat includes legitimate security researchers disclosing vulnerabilities in a way you don't like, you've just expanded the group of people we can call "black hats" almost arbitrarily. You're putting security researchers you have a normative disagreement with into the same group of people who commit actual fraud, steal identities and sell your credit card data.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#143
post #122

Earlier quoted context omitted.

Black hat isn't distinguished by failing to report vunlerabilities. It's distinguished by bad faith.

No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.

This is what wikipedia says:

A black hat hacker (or black-hat hacker) is a hacker who "violates computer security for little reason beyond maliciousness or for personal gain"

The personal gain part certainly fits with short selling the stock.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#144
post #141

Earlier quoted context omitted.

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

> Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though. A good way for companies to prevent this is to have a generous bug bounty program. Money is still transferred from the shareholders to the researchers, but then the company can impose conditions like delaying public disclosure for a reasonable time to prepare a fix.

If it's actually someone attempting to make money on a short or to benefit from a working relationship with a competitor, then a bug bounty program does nothing. No one can run a bounty program that pays out anywhere near as much as the information is actually worth to an adversary. Bug bounties work to engender a bit of good will among researchers and to provide some incentive to an otherwise neutral party to play ball. They don't mean shit to a hedge fund or a competitor in a multi-billion dollar industry.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#145
post #140
post #123

Earlier quoted context omitted.

This is the crux of it. The short disclosure window could hurt 3rd parties unnecessarily. Although I enjoy reading grandparent's counterpoint

More and more lately I'm leaning towards the, "responsible disclosure is a bunch of crap" camp. You have to be "in" to get the news. Even if you're "in" security people love to play info war power games and withhold things because it tickles their jimmies, etc. And don't forget, you're deliberately keeping a vulnerability secret from consumers during a long period where you have no idea who else knows about it. If I'…

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security.

It's sad to see people arguing for a return to those norms, especially since the rejection of them correlates with a renaissance in our understanding how to secure software.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#146
post #141

Earlier quoted context omitted.

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

> Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though. A good way for companies to prevent this is to have a generous bug bounty program. Money is still transferred from the shareholders to the researchers, but then the company can impose conditions like delaying public disclosure for a reasonable time to prepare a fix.

I'm not a finance expert, but my very lay person understanding of how financial markets work tells me that those would have to be some rather huge bounties. See e.g., the effect on Intel from earlier this year:

https://qz.com/1171391/the-intel-intc-meltdown-bug-is-hittin...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#147

24 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.

One difference between security researchers and "exploit creators", which is a term I think you just made up, is that exploit creators presumably release exploits.

Don't tell HD Moore or the Metapsloit team about this, though. They may cry themselves to sleep tonight.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#148
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

You mean to tell me my machine can be exploited if I let someone do one of the following.

1. Flash the BIOS 2. Have admin access

Holy shit, this calls for a full fledged panic!

I am very disappointed anandtech.com even bothered to give this smear campaign the time of day. If someone can flash your BIOS or has admin access then you already have way bigger problems.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#149
post #114
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…

That's fine, but it doesn't change the fact that the possibility (likelyhood?) of financial gain affects the authors credibility. Especially since it is already strained by other issues with this disclosure.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#150
post #136
post #106

Earlier quoted context omitted.

No they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.

black hats use them for bad, white hats use them for good. ideological discussions about disclosure policy aside, if they are doing this to manipulate stock prices and in doing so create a situation where more actual exploits occur, I'd say that is 'black hat' behavior.. the 'weaponization' is in the 'social engineering' of the market reaction, rather than a direct exploit in this case..

The problem with your first line is that it leaves the definition of black hat open to interpretation, when that is not how the word is actually used in the security industry or in popular reporting. Black hat activity specifically refers to criminal activity, which we can demonstrably perceive and attribute. By your reasoning, I am free to call security researchers black hats if they don't give vendors advance notice. You might disagree with that, but you can't say I'm wrong without making a normative argument about whether or not something is ultimately unethical. There is no categorical difference between me choosing to call people black hats if I disagree with their behavior and you calling these researchers black hats because they're doubling as activist investors.

On the other hand, this entire sideshow is bypassed if we use the well-established definition for "black hat", which refers exclusively to illegal behavior involving security vulnerabilities and online fraud. More to the point, reporting facts is not "market manipulation" (which is also a well established term) even if you want it to be, and "social engineering" is not the same as publicizing information with the intent to move the markets. Using these words in the way you are is the same as flippantly redefining them as you go along, with the result that the conclusion is quite brittle. There could be a strong argument that the behavior is unethical, but using these terms as you are doesn't help that point along, it hampers it.

Post reply on HN