Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

211–220 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#211
post #131
post #112

Earlier quoted context omitted.

Might the latter also depend on how you present it? As far as I can see this is only an exploit of secure boot if you are already on ring 0 level auth. Making a whole webpage with lots of graphics and whatnot, sending press releases all over and in general present it like a security flaw on the level of meltdown seems .. false? Probably court level material.. In any case it seems to have backfired as the stock is up.

I think the difference in facts you're talking about is a difference of degree, not category. In other words, it's not plainly false, there certainly is a vulnerability, it's just perhaps exaggerated. I could see a case being brought against the researchers on those grounds, but I'd be really surprised if anything came of it.

It could be interesting. Some of the flaws presented require you flash your bios, if I understand correctly. They are included with what are likely real flaws, but maybe it's enough for a case of misleading the public in part. To me it seems sort of like saying Ford engines have a tendency to blow up, but only after you've overwritten some engine firmware. By itself, not much to talk about, but when attached to something that has indications of being used to make money through stock changes, maybe is more likely to be looked at unfavorably by the SEC?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#212
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

You mean to tell me my machine can be exploited if I let someone do one of the following. 1. Flash the BIOS 2. Have admin access Holy shit, this calls for a full fledged panic! I am very disappointed anandtech.com even bothered to give this smear campaign the time of day. If someone can flash your BIOS or has admin access then you already have way bigger problems.

CTS-Labs is very forthright with its statement, having seemingly pre-briefed some press at the same time it was notifying AMD, and directs questions to its PR firm. The full whitepaper can be seen here, at safefirmware.com, a website registered on 6/9 with no home page and seemingly no link to CTS-Labs. Something doesn't quite add up here.

Anandtech is reporting on the situation more than the flaws. That does require covering what the flaws are though. Not covering it at all isn't exactly performing good journalism either.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#213
post #137

Earlier quoted context omitted.

Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.

It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction. That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.

The point is the counter balance the other side - companies have an incentive to overstate their upside and understate their risk.

Short sellers want the opposite. So they both present their best cases and let the public decide, much like how lawyers will defend their own clients to the last breath regardless of the amount of evidence against them

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#214

Earlier quoted context omitted.

So the 11 billion dollar vendor who shipped vulnerabilities in the first place gets to treat these problems as an externality, but 4 dudes in a basement who did a basic research project have to be restrained from speaking? I don't see how you get there from here.

An eye for an eye works only until everyone is blind. You seem to have several deeply misguided premises. 1. We don't know ARM knowingly shipped these chips although they were vulnerable. Bugs happen. 2. Even if this was the case, an individual can show, and ought to, show decency and empathy towards others. 3. This last comment of yours is a straw man and I doubt you are incapable of seeing this. You parent's argume…

I don't think you understand the dynamics here. I don't think anyone knowingly shipped vulnerabilities. That's an impossibly low bar: all you have to do to "not know" is to not spend any money on security verification. The complaint here is that AMD was outdone on verification by 4 dudes in a basement.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#215
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company

For example, a short seller last year revealed (through extensive research), that Valeant Pharmaceuticals was stuffing its channels and faking its finances. He placed a huge sort sell and went public with the damaging info - tanking the stock from $270 to $12 and made a ton of profit off of it: https://www.nytimes.com/2017/06/08/magazine/the-bounty-hunte....

Without this incentive, why would anyone bother to reveal damaging info? You're placing your self as a target with no reward. The payment is the natural balance of the market.

So yes, this research firm is connected w a hedge fund, and they have a very vested interest. But that doesn't make their claim untrue

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#216
post #122

Earlier quoted context omitted.

No, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.

No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.

Words aren't defined by any authority. Their historical and present common uses however are documented by dictionaries et al. The most authoritative source on the term "black hat" is probably esr's jargon file: http://www.catb.org/jargon/html/B/black-hat.html

To save the click: "1. [common among security specialists] A cracker, someone bent on breaking into the system you are protecting."

Your (and hdyr's) looser version is not in common usage and in that sense is wrong.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#217
post #114
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensiv…

It seems to me that disclosing vulnerabilities is in a different category from disclosing fraud. In the latter case, the only entities that suffer materially is the fraudulent organization and its investors, in the former you have the additional potential to expose all users of the vulnerable software to risk.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#218
post #216

Earlier quoted context omitted.

No one defined "black hat". Just what authority do you think sets that? There is none. Black hat is not a standard to which people are scrutinized.

Words aren't defined by any authority. Their historical and present common uses however are documented by dictionaries et al. The most authoritative source on the term "black hat" is probably esr's jargon file: http://www.catb.org/jargon/html/B/black-hat.html To save the click: "1. [common among security specialists] A cracker, someone bent on breaking into the system you are protecting." Your (and hdyr's) looser ver…

>Words aren't defined by any authority

This is exactly my point. The Jargon file is pretty dated and imo the definition given there isn't really adequate.

My looser version is indeed in common usage. If nothing else 5 HN users seem to agree with my definition enough to upvote my initial comment on the matter.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#219

Earlier quoted context omitted.

Vulnerability and Exploit are different.

Can you demonstrate a vulnerability without producing an exploit? You have to provide a poc to demonstrate it to others at least, no? Two sides of the same coin

You can release the concept and description of a vulnerability without releasing an operational exploit.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#220

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

If you look at the metadata of both the white paper and the analysis, you can see that the creation time of them is only 2 hours, 50 minutes apart.

And that's the creation date, not even when they were published.

https://pastebin.com/CcDTz0hB

Post reply on HN