Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

271–280 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#271
post #256

Earlier quoted context omitted.

Can you point to a javascript example? I can think of a number of approaches, but nothing I could catergorise as trivial.

First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome

> Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#273

Earlier quoted context omitted.

First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome

> Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...

SharedArrayBuffer was disabled exactly because vulnerabilities like this are easily exploitable (but there are POCs that don't depend on it).

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#274

Earlier quoted context omitted.

I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…

”The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws.” I know everyone in my family is ignorant of this “disclosed” security flaw and is powerless to mitigate the vulnerabilities disclosed on their own. Even if they did know to “turn off their computer” as someone said, are they supposed to wait until someone calls them to tell them a patch…

How many vulnerabilities are you capable of finding in software that everyone in your family uses, and can't find for themselves? I'm sure the number is not zero. Is it unethical for you not to go look for them?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#275
post #205

A security researcher claims to have access to the full (non-public) technical report as well as PoC exploits for it. He says they're legit, and they are flaws, not just "you can do admin things with an admin password". https://twitter.com/dguido/status/973628511515750400 Sounds like the capabilities include the ability to jump outside a VM sandbox, take over the PSP, and pivot to the firmware or BIOS exploits. https…

How do we know this guy's not a conspirator?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#276

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

Hmm ... I was more tempted to dig into connections between the Israeli firm and Intel but your analysis is way better!

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#277

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

Why is AMD 1.04% up today then (while technology index is -1.16%)?

https://finance.google.com/finance?q=amd

    AMD	$11.64

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#278

Earlier quoted context omitted.

No obligation to vendors, no obligation to the public, so what are your ethical standards exactly? It sounds like committing crimes is it, but that’s a legal standard and not an ethical one. At what point are you less of a researcher and more of a sociopath with a keyboard? What makes researching software vulnerabilities such a uniquely non-ethical undertaking compared to all other forms of research? You seem like a…

In exactly what way are you harmed by someone discovering a vulnerability --- that existed whether or not they did the work --- and then telling you about it ? You're arguing that the force of law should prevent you from learning inconvenient things about the software you use.

You are not harmed by someone discovering a vulnerability and telling you about it. Obviously that benefits you rather than harming you.

You are harmed by them discovering a vulnerability and telling the world about it.

And if they discover a vulnerability and tell both you and the rest of the world, the harm may easily outweigh the benefit.

Suppose I go wandering around the city where you live, checking for unlocked house doors. I find that you've left your front door unlocked and gone on holiday. I then wander the streets shouting "Thomas's house is unlocked and no one's at home!". I also phone you up to let you know your house is unlocked.

It was your fault, not mine, that the house was unlocked and no one at home to deter burglars. In principle, anyone else could have come along and burgled your house, if they'd found it before I did. None the less, I think that in this scenario I have done you wrong.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#280

Earlier quoted context omitted.

First hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome

> Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...

Every single browser had to disable that feature because of those flaws.
Post reply on HN