https://blogs.msdn.microsoft.com/oldnewthing/20060508-22/?p=...
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
281–290 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#282A security researcher claims to have access to the full (non-public) technical report as well as PoC exploits for it. He says they're legit, and they are flaws, not just "you can do admin things with an admin password". https://twitter.com/dguido/status/973628511515750400 Sounds like the capabilities include the ability to jump outside a VM sandbox, take over the PSP, and pivot to the firmware or BIOS exploits. https…
How do we know this guy's not a conspirator?
https://www.trailofbits.com/research-and-development/publish...
Ian Cutress of Anandtech appears to be quasi-vouching for Dan Guido. Ian is also interviewing CTS Labs tomorrow morning, and looking for questions.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#283Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…
That said, unless the whole "research" is fake, I wonder if we could be seeing more such tactics in the future against tech companies, and whether or not that would give them an immense incentive to care about security - or risk getting ruined in the stock market.
Honestly, such a huge incentive may actually be needed to get most companies to get about security. The money equation needs to make sense to them. Right now most think investing the absolute minim amount in security for compliance reasons is already too much money wasted on security. If this were to become common, I think maximizing security would actually start looking quite profitable to them.
I mean, this research is already saying there are some backdoors in AMD's chips. I imagine in the future, companies would be way more careful about allowing backdoors in their products, whether intentionally or by mistake, if they knew they risked getting their stock crushed.
So yeah I just like to play with this idea a little bit. So far this revelation doesn't seem to have had the "desired" effect by the backers of the research, though, but we'll see. I just want to know whether or not the research is real, so I'll wait for AMD's confirmation. I assume AMD wouldn't try to lie to us about it, because there are now probably at least a dozen security teams trying to pick AMD's chips apart, so the flaws would be found soon enough, if real.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#284Legal question: Insider trading claims might be difficult since you can claim the vulnerabilities were public knowledge waiting to be discovered, but... Can you trade on knowing the security disclosure timeline prior to your publication of the vulnerability? That would seem to be insider knowledge until AMD authorizes publication. E.g. I've got knowledge that AMD likely wouldn't be able to fix the flaws prior to my d…
Insider trading usually implies coming into possession of confidential information and acting on it. Trading on non-public information that results from your own research and then announcing it is not illegal. Imagine someone buying stock and then saying the company is good. Not very controversial is it. Warren Buffet does it. Shorting stock and saying the company is bad is just the flip side of it. In fact, there ar…
Correct. I'm not referring to this. I'm referring to trading on information discerned from communications with e.g. AMD but prior to disclosure of the vulnerability, especially if those communications which establish e.g. timelines are only disclosed after trading
Hence my point about trading upon understanding AMD's response timeline e.g. from emailing them.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#285Earlier quoted context omitted.
Pity that vast incentive didn't seem to work out when they promoted all these chips as having "Firmware Trusted Platform Module", "Secure Encrypted Virtualization", "AMD Secure Processor", and "AMD Secure OS" as features. AMDs incentive, like any corporation, is to maximise shareholder value. Same as any tiny little security research firm. If a research firm can maximise their profit buy discovering vulnerabilities a…
CPU's have real value. As to ethics that's mostly irrelevant to this discussion. Both sides could have ethical behavior, I am simply pointing out which side has the larger incentives to exaggerate. After all the stock could drop and a short seller could still lose money. They need the stock to drop a lot even over a minor issue.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#286Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#287Earlier quoted context omitted.
Just look at what Citron Research did to Shopify last year. They tanked the stock from $120 to $93 just based on false accusations that they put out in a "report". Now Shopify is now closer to $150...so their plan worked.
> just based on false accusations that they put out in a "report". If it's false information, isn't that classic stock manipulation? I thought for it to be legal to make money on the stock it had to be both accurate and publicly available (if potentially hard to put together)?
Watch the video and see for yourself: http://citronresearch.com/citron-exposes-the-dark-side-of-sh...
That video by itself tanked the stock for many many weeks, until they finally reported quarterly results and it started climbing again.
I'm glad the CEO didn't feed the trolls by acknowledging this report in any depth.
Also shows how irrational the stock market is in the short term.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#288Wouldn't take much to use stealth proxy operatives to carry out such a smear, and guess who benefits the most from a smear of AMD ?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#289Earlier quoted context omitted.
What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html
Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...
They didn't blow full technical details on this exploit after 24 hours, they went public with a summary... one that's so high-level that many people are even doubting they exist. That's not exactly dumping a zero-day on the internet either.
There's a whole lot of shooting-the-messenger going on with this topic. Making plays against the stock is scummy and possibly illegal, but that doesn't make the exploits here any less real (assuming they are). These are actually quite serious breaks, potentially VMs can jump the sandbox straight into SMM mode and PSP, so it actually is much more severe than just "root password lets you do root things".
https://twitter.com/c7zero/status/973668616183754753
There is a long and storied history of showing the disadvantages of your competitor's products. Edison went on a campaign against Westinghouse's AC electricity, culminating in him electrocuting an elephant to death to demonstrate how dangerous it is.
Right now we need more spotlights on computer security than ever, and as long as it gets bugs patched (hardware, software, or firmware) I don't really care who's doing it or what their short-run motivations are. If AMD won't secure their code appropriately and Intel wants to call them out, fine. If Intel is leaking timings through sidechannels and AMD wants to call them out on it, fine.
And if we want to throw stones here, it was AMD who blew the embargo on Meltdown a week early because they wanted to force a response from Intel at CES... different in degree, not really in kind.