Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

261–270 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#261
post #241
post #184

Linus' reaction: https://plus.google.com/+LinusTorvalds/posts/PeFp4zYWY46

It's quite unsettling that Linus thinks as much of security in general, given that he maintains a kernel and he's responsible for accepting its security modules that are next to unusable because of their complexity. Could his general disbelief lead to a (kind of) dismissive attitude in this respect? Keep in mind he's the one that would never properly disclose of a security fix - instead of saying which problem is fix…

People who work in vulnerability research generally just point and laugh at him. His opinion on this doesn't matter.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#262
post #257

Earlier quoted context omitted.

In exactly what way are you harmed by someone discovering a vulnerability --- that existed whether or not they did the work --- and then telling you about it ? You're arguing that the force of law should prevent you from learning inconvenient things about the software you use.

> and then telling you about it? The argument against your position that people are trying to get across to you is not that. It is that publication of vulnerability without giving heads-up and time to prepare solution to the vendor greatly increases the risk that a user will be harmed by attackers exploiting the public knowledge. Often substantial number of users are not going to mitigate or resolve the problem witho…

And if I don't want to jump through whatever random hoops message board nerds have erected and just decide not to disclose at all, exactly how are you better off?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#263

Earlier quoted context omitted.

Does everyone who releases drivers release buggy drivers?

Close to 100% of software has bugs. Almost all drivers have bugs. Anything that prioritises company profit and release dates over complete correctness in sectors where bugs == deaths, will have bugs. (And even those sectors are not magically immune) So yes - I expect they do.

So are vendors who release buggy drivers not "dicks" for the same reason that chip manufacturers aren't?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#264
post #63

Earlier quoted context omitted.

No, I'm just noticing again that people who don't don't do a lot of vulnerability research have a lot of interesting opinions about the professional norms of people who do that work. But you never know --- maybe they do a lot of research, in which case, yes, their opinion on security research norms is a lot more interesting to me.

Matasano and you got owned quite frequently back in the day. Should be judge you or your company or your opinions based on that too?

Sick burn, dude.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#265
post #256

Earlier quoted context omitted.

Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.

Can you point to a javascript example? I can think of a number of approaches, but nothing I could catergorise as trivial.

First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#266

Earlier quoted context omitted.

And at other times 90 days maybe inadequately short. But 90 is just a round number someone at Google thought is a good idea. And now it's become 'standard'. I can go with immediate, or I can go with never. But realize that every vuln is different, and their impact (or hardship of writing or applying patches) may not always be fully understood by stakeholders involved before or immediately after the details are releas…

90 days is good amount of time to research a vuln and prepare fixes. We could always have the government regulate this instead though, instead of being professionals and self-regulating.

And that would end so well. Nothing like infringing on the 1st Amendment (if you're in the USA).

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#267
post #247

Earlier quoted context omitted.

> Responsible Disclosure is caring about the vendor, whereas full disclosure gives other people the chance to take action on their own to remove themselves from harm. That is true, but you missed the other side of the argument. Coordinated disclosure is preferable also to a part of users/customers. Significant part of them have no understanding or incentive enough to mitigate on their own. So the question the discove…

What about the flaws that aren't unintuitive? What about the bog standard integer overflows vendors routinely leave in code because they won't pay what it costs to ensure they don't ship them?

So let me get this straight: are you arguing that because some portion of bugs each year is due to vendor negligence, it is OK for us security researchers to make the vulnerabilities public and expose users dependent on the vendor any time we want?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#268
post #267

Earlier quoted context omitted.

What about the flaws that aren't unintuitive? What about the bog standard integer overflows vendors routinely leave in code because they won't pay what it costs to ensure they don't ship them?

So let me get this straight: are you arguing that because some portion of bugs each year is due to vendor negligence, it is OK for us security researchers to make the vulnerabilities public and expose users dependent on the vendor any time we want?

Obviously, yes. Your "some portion of" should read "virtually all".

I answered your question. But you didn't answer my question.

What about the flaws that aren't unintuitive? What about the bog standard integer overflows vendors routinely leave in code because they won't pay what it costs to ensure they don't ship them?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#270
post #93

Earlier quoted context omitted.

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…

I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…

”The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws.”

I know everyone in my family is ignorant of this “disclosed” security flaw and is powerless to mitigate the vulnerabilities disclosed on their own. Even if they did know to “turn off their computer” as someone said, are they supposed to wait until someone calls them to tell them a patch is ready?

Disclosing a vulnerability for profit at the expense of everyone else is a shitty thing to do. Would giving AMD a few days to fix it have hurt as many people as giving them one day?

Post reply on HN