Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

181–190 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#181
post #155

Earlier quoted context omitted.

Excellent, great citation! Now, precisely what did the security researchers hack for their own gain, and precisely which computer's security was violated? If we can call them "hackers" just because they ostensibly compromised their own hardware or software as a proof of concept for the vulnerability research, does that mean that all of Google's Project Zero consists of hackers and black hats because they get paid (pe…

Project Zero practices responsible disclosure. They do not make money from the exploitation of the companies whose software/hardware they find flaws in. The difference is very stark and you are being deliberately obtuse.

> They do not make money from the exploitation of the companies whose software/hardware they find flaws in.

Right, and neither did these researchers.

In point of fact, no, the difference really isn't all that stark. It's a difference of degree, not category. You apparently have a problem with disclosing vulnerabilities without providing advanced notice to the vendor, and you consider it especially distasteful to do so if you're financially benefitting from that. But all of that still comprises vulnerability disclosure, which is categorically different from actively using a vulnerability to compromise users as part of a criminal enterprise.

We can go back and forth like this all day, because every time someone bends the definition of black hat to fit something they disagree with, I can form a counterpoint which is technically true but which no one is willing to call black hat behavior, like Google Project Zero. On the other hand, if we use the definition of black hats as criminals engaging in online fraud, augmented by security vulnerabilities, then of course Google Project Zero doesn't qualify. You're going to have a very difficult time broadening the scope of this terminology to suit your definition without accidentally including groups you don't want to be in the same bucket.

And that's precisely my point. If you broaden terms too much, like "black hat" to "stuff with computers in bad faith", we can just weasel in whatever satisfies the definition or agrees with our personal viewpoint. Black hat criminals do not engage in debatable behavior, because it's strictly illegal and directly profits at the expense of other people. At best, all you can do is formulate an abstract argument about people being harmed by rapid disclosure, but that actually comes down to a debate of disclosure guidelines, not a debate of activist investing.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#183
post #181

Earlier quoted context omitted.

Project Zero practices responsible disclosure. They do not make money from the exploitation of the companies whose software/hardware they find flaws in. The difference is very stark and you are being deliberately obtuse.

> They do not make money from the exploitation of the companies whose software/hardware they find flaws in. Right, and neither did these researchers. In point of fact, no, the difference really isn't all that stark. It's a difference of degree, not category. You apparently have a problem with disclosing vulnerabilities without providing advanced notice to the vendor, and you consider it especially distasteful to do s…

>Right, and neither did these researchers.

I'm just going to conclude that you are trolling at this point and try to forget this headache of a thread.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#185
post #173

Earlier quoted context omitted.

> There is a "reasonably accepted" definition of black hat, by your reasoning, and it is: someone who uses computers in bad faith. Speaking as someone who 1) works in the security industry, 2) has managed corporate disclosure programs as an internal security engineer, 3) has run a security consulting firm working with many companies, and 4) has reported security vulnerabilities in disclosure programs; no, that's not…

I think the "security industry" has a delusional image of themselves and regard most of them as grey hats at best. An insider's opinion on what constitutes black hat is not particularly impressive to me. And this is not a generalized disagreement of ethics. Bad faith is has a specific meaning and you are unreasonably stretching it.

> I think the "security industry" has a delusional image of themselves and regard most of them as grey hats at best.

This criticism of the industry might hold more weight if you actually evidenced a willingness to use terminology according to its accepted usage, not as a tool to advance your ethical opinions.

> And this is not a generalized disagreement of ethics.

It actually is, because I strictly disagree that either of 1) trading on bad news, like security vulnerabilities, or 2) disclosing vulnerabilities without notifying the vendor are unethical. You're free to disagree! Your opinion is just as valid as mine; the thing is, we don't define words based on opinions, because then we'd never get anywhere, and we could label people we don't like whatever term we know other people don't like, even if we don't share the same definition of the term. By calling people who do either of #1 or #2 black hats, you're exercising rhetoric that puts them in with actual criminals, doing actual illegal things just because they are doing something you disagree with.

> Bad faith is has a specific meaning and you are unreasonably stretching it.

Okay. I guess I'm free to also call scientists working on whatever thing I disagree with pseudoscientists then, just because I find their work ethically unsettling. Better yet, I could call them criminals.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#186

24 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.

Vulnerability and Exploit are different.

Can you demonstrate a vulnerability without producing an exploit? You have to provide a poc to demonstrate it to others at least, no?

Two sides of the same coin

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#187
post #155

Earlier quoted context omitted.

This is what wikipedia says: A black hat hacker (or black-hat hacker) is a hacker who "violates computer security for little reason beyond maliciousness or for personal gain" The personal gain part certainly fits with short selling the stock.

Excellent, great citation! Now, precisely what did the security researchers hack for their own gain, and precisely which computer's security was violated? If we can call them "hackers" just because they ostensibly compromised their own hardware or software as a proof of concept for the vulnerability research, does that mean that all of Google's Project Zero consists of hackers and black hats because they get paid (pe…

[deleted]

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#188
post #74

Earlier quoted context omitted.

> Could something like this be considered inside information? No, illegal insider trading refers to trading on inside information when you have a confidentiality agreement or a fiduciary duty. Information asymmetry is insufficient (or else it would be virtually impossible to profitably trade at all). > Or is it legal to actively manipulate stock prices to ones benefit in this way? The way you're presenting this is a…

What if it's not false but misleading? That sounds closer to what they are doing here. Sure they included a ridic disclosure agreement that you apparently agree to have read if you continue to read their webpage, and it says something along the lines of "this is our opinion". It feels slimy and gross.

"Slimy" and "gross" are not nearly sufficient for either insider trading or market manipulation. I don't particularly like the way these researchers are acting either, but that's actually because I don't like vulnerability impact being exaggerated and over-hyped. The other stuff doesn't bother me too much.

If the news pushing a stock price is so misleading that it's categorically different from the truth, then I could see a case for market manipulation being brought against them. But I doubt that will happen, because unfortunately people have broad latitude to portray vulnerabilities however they'd like as long as they're convincingly authentic.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#189
post #81
post #33

Earlier quoted context omitted.

Basically a follow the money situation. Could something like this be considered inside information? Or is it legal to actively manipulate stock prices to ones benefit in this way?

To add to the other comments here, a recent high profile case of something similar was Bill Ackman shorting Herbalife. Basically, he shorted the stock and then went to the media with his research showing that he believed Herbalife to be a pyramid scheme. Ultimately, I believe he lost money on the whole fiasco, but it's not an uncommon strategy. The whole thing made the news after a particularly amusing exchange betwe…

Regarding Ackman vs Herbalife, the old adage comes to mind: The market can stay irrational longer than you can remain solvent.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#190

Earlier quoted context omitted.

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…

I agree, but I am curious if you have any suggestions on how we should be handling disclosure?

Don't sue people if they publish vulnerabilities without any notification to the vendor, as long as they never overstepped and exploited it themselves.
Post reply on HN