Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

161–170 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#161
post #78

Earlier quoted context omitted.

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

A new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices…

Do you know where the line is between what e.g. Citron Research is doing and what is considered slander? (I assume they walk a very thin line in order to not get sued)

Their Shopify video [1] for example is not the typical „research report“ with lots of specifics but more of a personal opinion with rather broad accusations.

[1] http://citronresearch.com/citron-exposes-the-dark-side-of-sh...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#162
post #21

Earlier quoted context omitted.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

> "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before. Individuals sometimes do this, security companies very rarely - and both are shunned by the infosec community at large when they do so, as this is very unethical behaviour. They registered the domain a couple of weeks ago - why give AMD only 24 hours notice? In this case it does seem highly likely there is some stock market skulld…

No, they are not "shunned by the infosec community", no matter how nice that narrative sounds to you.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#163
post #140

Earlier quoted context omitted.

More and more lately I'm leaning towards the, "responsible disclosure is a bunch of crap" camp. You have to be "in" to get the news. Even if you're "in" security people love to play info war power games and withhold things because it tickles their jimmies, etc. And don't forget, you're deliberately keeping a vulnerability secret from consumers during a long period where you have no idea who else knows about it. If I'…

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…

I agree, but I am curious if you have any suggestions on how we should be handling disclosure?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#164
post #19
post #5

> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time. 90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional. Full, immediate disclosure is responsible.

And the users downstream of bugs that are made more widely vulnerable--because, as anyone who saw how, as an example, previously rare MitM attacks became commonplace after Firesheep etc. were publicized, obscurity is in fact a component of security --are...? Well, fuck 'em, I guess. Responsible disclosure, contrary to the super-cool leet kid notions expressed by people with who choose to exhibit an underdeveloped soc…

[deleted]

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#165
post #66

Earlier quoted context omitted.

Mentioned in another comment, but from their management page: http://www.cts-labs.com/management-team > He [Yaron, CFO] is also the founder and Managing Director of NineWells Capital, a hedge fund that invests in public equities internationally. I wonder how linked the companies are - is this basically a vulnerability research company as a research arm of a hedge fund?

It sure seems that way. It wouldn't be the first; look, for instance, at Justine Bone's MedSec.

There was also Mark Cuban's Sharesleuth: https://www.wired.com/2007/09/mf-sharesleuth/

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#166

24hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.

What's wrong with full disclosure? Ryzen owners ought to be informed ASAP that they're (possibly) vulnerable.

What can AMD do with 24h notice? Could they even verify the veracity of the claim in that time?

As am AMD system owner, I would much prefer that big flaws were disclosed in a coordinated manner with AMD - giving them a fair chance to verify and find a solution, rather than giving bad actors a head start.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#167

Earlier quoted context omitted.

This is probably where we diverge. From where I stand, "end users" are incapable of making a meaningful decision about security at this level. It would be awesome if they weren't, and god knows I have spent a decent amount of time in my life trying to bootstrap people into such a position, but it doesn't...like...work. There is a computing priesthood, as much as we have tried to democratize this stuff, and it's all g…

So the 11 billion dollar vendor who shipped vulnerabilities in the first place gets to treat these problems as an externality, but 4 dudes in a basement who did a basic research project have to be restrained from speaking? I don't see how you get there from here.

I don't get how you get to me thinking the vendor gets to treat these problems as an externality? I am all in favor of slagging vendors who release buggy shit. For hardware (and some software) manufacturers I'd be in favor of significant legal remedies available to people who purchase hardware later found to contain security vulnerabilities.

But I think that should be done after mitigations are in place to protect end users, or if the vendor is not taking good-faith steps to mitigate the problem.

And I am not saying one should be "restrained from speaking" at all. I am saying that choosing to do so makes one an asshole, and that decent people should strive to not be assholes.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#168
post #19

Earlier quoted context omitted.

And the users downstream of bugs that are made more widely vulnerable--because, as anyone who saw how, as an example, previously rare MitM attacks became commonplace after Firesheep etc. were publicized, obscurity is in fact a component of security --are...? Well, fuck 'em, I guess. Responsible disclosure, contrary to the super-cool leet kid notions expressed by people with who choose to exhibit an underdeveloped soc…

Here's the strongest version of the claim that I understand: 1. All of the relevant people, i.e. "the users downstream of bugs" are already vulnerable . 2. It's possible, maybe even probable (or likely ), that people, other than the researchers that are disclosing the vulnerability, have also discovered the same vulnerability and, furthermore, that those others can exploit the vulnerability. 3. Every delay in disclos…

I think that is a fair depiction. I think also that [3] requires that people are capable, en masse, of protecting themselves from those bad actors.

I think a cursory look at the world indicates that this is not even adjacent to reality.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#169
post #144
post #141

Earlier quoted context omitted.

> Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though. A good way for companies to prevent this is to have a generous bug bounty program. Money is still transferred from the shareholders to the researchers, but then the company can impose conditions like delaying public disclosure for a reasonable time to prepare a fix.

If it's actually someone attempting to make money on a short or to benefit from a working relationship with a competitor, then a bug bounty program does nothing. No one can run a bounty program that pays out anywhere near as much as the information is actually worth to an adversary. Bug bounties work to engender a bit of good will among researchers and to provide some incentive to an otherwise neutral party to play b…

Not unless the bounties are large enough to attract the attention of a hedge fund.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#170
post #63

Earlier quoted context omitted.

Nice non-sequitur. Somehow the limiting factor on the ability of someone to judge professionalism is the number of papers they've written?

No, I'm just noticing again that people who don't don't do a lot of vulnerability research have a lot of interesting opinions about the professional norms of people who do that work. But you never know --- maybe they do a lot of research, in which case, yes, their opinion on security research norms is a lot more interesting to me.

I am not a security researcher, and I do not speak for the person you are replying to, but I do believe that Intel's documented history of unethical, anticompetitive practices against AMD, for example, deliberate compiler handicapping for non Intel CPUs[1], is enough evidence to establish at least some suspicion regarding these results, especially considering the short warning given to AMD before public disclosure.

I also wonder, what is the purpose of such white hat operations if vulnerabilities are disclosed publicly without anywhere near adequate time for a fix? Isn't SOP to give more time before going public?

1.https://en.m.wikipedia.org/wiki/Intel_C%2B%2B_Compiler#Criti...

Post reply on HN