Linus' reaction: https://plus.google.com/+LinusTorvalds/posts/PeFp4zYWY46
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
241–250 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#242Wild guess / conspiracy theory: Intel, afraid of the damage to their image just made worse by diminished performance advantage compared to AMD )due to Meltdown), fearing long-term market loss, quickly found ways to tackle the issue by, instead of pedaling to regain trust, damaging a competitor's image. It seems like a reasonable long game to support and perhaps steer the disclosure of AMD vulnerabilities that CTS-lab…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#243Earlier quoted context omitted.
Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…
People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…
So are you talking about AMD being dicks by releasing buggy chips, or the researchers somehow being dicks for finding out?
Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the vendor 90 days notice before telling the public?
While I think it's reasonable and appropriate professional practice for _some people/teams_ to go down the "coordinated disclosure" path (I think the world is a better place for having Tavis Ormandy disclose the way he chooses to), it does without doubt benefit the company who's products are flawed more than the researcher or the public. Anybody who knows they work at a firm that's going to be described dismissively like AMD here did "This company was previously unknown to AMD" is quite likely correct to publish-and-be-damned, because you can bet there's a non-zero chance that AMD's response to non-public disclosure is going to include either stonewalling and stringing the problem out as long as possible, or lawyering up ad threatening to sue the "previously unknown to AMD" company into oblivion.
If you don't want public disclosure of security flaws about your products, either don't make flawed products or don't ship them to the public. Especially if some of the key selling features of said product include bullet points like "AMD Secure OS".
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#244Earlier quoted context omitted.
Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…
3. The vulnerabilities are minor, barely worse than normal expected behaviour; just enough to call them vulnerabilities. All these "exploits" consist of using ultra-privileged access (signed device drivers, or flashing the BIOS) for bad purposes. In the white paper, many attacks are hypothetical and many phrases are vague and slippery, suggesting the "researchers" barely achieved execution of something, not real payl…
Suggesting this is "just hypothetical" because "nobody is going to get physical access or code execution in a signed driver" is pretty shortsighted in my opinion...
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#245Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#246Earlier quoted context omitted.
People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…
> I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick So are you talking about AMD being dicks by releasing buggy chips, or the researchers somehow being dicks for finding out? Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the…
Everybody releasing chips releases buggy chips. It's the current reality of both hardware and software. Unless they do it maliciously, they're not dicks.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#247Earlier quoted context omitted.
I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…
> you are a better person than that I don't think this is an appropriate way to argue. Sounds like if he disagrees with you, he is somehow below standard. > It's just...minimal decency, to care about other people. Alerting folks to the danger that they face is one way to do so. Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remov…
That is true, but you missed the other side of the argument. Coordinated disclosure is preferable also to a part of users/customers. Significant part of them have no understanding or incentive enough to mitigate on their own. So the question the discoverer of a bug then faces is 'how much headstart should I give the vendor and the users that depend on the vendor, before I make this public'? This has no universal answer, it may depend on how long the bug is out there and what kind of users may be harmed. But it is easy to see that a little headstart in terms of weeks is more reasonable than headstart=0, especially for bugs that are out there for years.
> why not argue for Responsible Development? This is where the outcry should be. Flaws in products come about because they are shipped before they are finished.
Flaws are not always due to cutting corners. Some bugs in computers are very unintuitive and it could be years before they manifest. More responsible development seems like a good idea, but again, this ignores the other part of the problem - major group of users do not understand the intricacies of development and are not willing to buy more 'responsible' product, if it is 5years behind the newest trend and costs 5x as much.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#248Earlier quoted context omitted.
> They do not make money from the exploitation of the companies whose software/hardware they find flaws in. Right, and neither did these researchers. In point of fact, no, the difference really isn't all that stark. It's a difference of degree, not category. You apparently have a problem with disclosing vulnerabilities without providing advanced notice to the vendor, and you consider it especially distasteful to do s…
>Right, and neither did these researchers. I'm just going to conclude that you are trolling at this point and try to forget this headache of a thread.
On the other hand I agree with responsible disclosure. And I think that should be made mandatory by law.
And finally, I also agree with some fines for companies allowing these holes to exist for so long. Especially those discoverable by 4 (more or less) random guys.
This is not black and white situation, so don't look for easy conclusions.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#249Earlier quoted context omitted.
There is far far more incentive for AMD and its partners to understate the severity.
I disagree. AMD needs to maintain it's reputation over time. Short sellers make their profit over a few hours/days and don't care if they are proven wrong. So, AMD has vastly more incentive to be accurate than short sellers.
AMDs incentive, like any corporation, is to maximise shareholder value. Same as any tiny little security research firm. If a research firm can maximise their profit buy discovering vulnerabilities and shorting stock before disclosing them, is that any ethically worse than a chip company rushing out flawed hardware with big flashy marketing bullet points claiming how secure they are?
(I'm not saying short-selling chip vendor stocks on the back of vulnerabilities is a way I'd choose to make a living, but surveillance capitalism doesn't seem an "ethically better" industry to work in either...)
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#250Earlier quoted context omitted.
> you are a better person than that I don't think this is an appropriate way to argue. Sounds like if he disagrees with you, he is somehow below standard. > It's just...minimal decency, to care about other people. Alerting folks to the danger that they face is one way to do so. Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remov…
> Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remove themselves from harm. That is true, but you missed the other side of the argument. Coordinated disclosure is preferable also to a part of users/customers. Significant part of them have no understanding or incentive enough to mitigate on their own. So the question the discove…