Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

171–180 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#172

24 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.

Vulnerability and Exploit are different.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#173
post #134

Earlier quoted context omitted.

There is a reasonably accepted definition for what a "black hat" is. I don't particularly agree with conceptually bucketing people into black hats or white hats, but the paradigm has an existing meaning. In any case, if we go by what you're saying, then anyone can define "black hat" to mean whatever they want, which means it's a meaningless and unproductive concept to throw around in conversation. Your assertion is i…

There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith.

> There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith.

Speaking as someone who 1) works in the security industry, 2) has managed corporate disclosure programs as an internal security engineer, 3) has run a security consulting firm working with many companies, and 4) has reported security vulnerabilities in disclosure programs; no, that's not the reasonably accepted definition. I can't think of any colleague I've ever worked with off the top of my head, nor any widely read security-focused periodical (like Krebs), who would use the term "black hat" for such a generalized disagreement of ethics.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#174
post #83

Earlier quoted context omitted.

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

> They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Seriously. AMD stock is trading up 3+% at the time of my comment, and it's climbed since the disclosures this morning. Something tells me this backfired. Discl: I've been long AMD for a long frickin' time.

In the long term, the market is a weighing machine. Time will tell.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#175
post #173

Earlier quoted context omitted.

There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith.

> There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith. Speaking as someone who 1) works in the security industry, 2) has managed corporate disclosure programs as an internal security engineer, 3) has run a security consulting firm working with many companies, and 4) has reported security vulnerabilities in disclosure programs; no, that's not…

I think the "security industry" has a delusional image of themselves and regard most of them as grey hats at best. An insider's opinion on what constitutes black hat is not particularly impressive to me. And this is not a generalized disagreement of ethics. Bad faith is has a specific meaning and you are unreasonably stretching it.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#176
post #137

Earlier quoted context omitted.

It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.

There is far far more incentive for AMD and its partners to understate the severity.

On an individual level, it's much less I'd think. Inciting a panic could be life changing amounts of money for the researchers, paid out by the hedge fund returns.

AMD isn't going to crash and burn over these flaws anymore than Intel (at 5 year high) did.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#177
post #137

Earlier quoted context omitted.

It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.

There is far far more incentive for AMD and its partners to understate the severity.

I disagree. AMD needs to maintain it's reputation over time. Short sellers make their profit over a few hours/days and don't care if they are proven wrong.

So, AMD has vastly more incentive to be accurate than short sellers.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#178
post #74
post #33

Earlier quoted context omitted.

Basically a follow the money situation. Could something like this be considered inside information? Or is it legal to actively manipulate stock prices to ones benefit in this way?

> Could something like this be considered inside information? No, illegal insider trading refers to trading on inside information when you have a confidentiality agreement or a fiduciary duty. Information asymmetry is insufficient (or else it would be virtually impossible to profitably trade at all). > Or is it legal to actively manipulate stock prices to ones benefit in this way? The way you're presenting this is a…

What if it's not false but misleading? That sounds closer to what they are doing here. Sure they included a ridic disclosure agreement that you apparently agree to have read if you continue to read their webpage, and it says something along the lines of "this is our opinion".

It feels slimy and gross.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#179
post #169
post #144

Earlier quoted context omitted.

If it's actually someone attempting to make money on a short or to benefit from a working relationship with a competitor, then a bug bounty program does nothing. No one can run a bounty program that pays out anywhere near as much as the information is actually worth to an adversary. Bug bounties work to engender a bit of good will among researchers and to provide some incentive to an otherwise neutral party to play b…

Not unless the bounties are large enough to attract the attention of a hedge fund.

> Not unless the bounties are large enough to attract the attention of a hedge fund.

Which they should be if the alternative is a much larger loss to the company's share value. The shareholders come out ahead to pay five million on a bug bounty if the alternative is to lose a billion dollars in market cap.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#180

Earlier quoted context omitted.

> "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before. Individuals sometimes do this, security companies very rarely - and both are shunned by the infosec community at large when they do so, as this is very unethical behaviour. They registered the domain a couple of weeks ago - why give AMD only 24 hours notice? In this case it does seem highly likely there is some stock market skulld…

No, they are not "shunned by the infosec community", no matter how nice that narrative sounds to you.

No need for the attitude.

Just take a look on twitter at what prominent members of the community are saying - they are not impressed with this behaviour. I'm also a member of that community, and hold the same view.

The vast majority of the infosec community promote coordinated disclosure.

Post reply on HN