Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

301–310 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#301

Earlier quoted context omitted.

Insider trading usually implies coming into possession of confidential information and acting on it. Trading on non-public information that results from your own research and then announcing it is not illegal. Imagine someone buying stock and then saying the company is good. Not very controversial is it. Warren Buffet does it. Shorting stock and saying the company is bad is just the flip side of it. In fact, there ar…

> Trading on non-public information that results from your own research and then announcing it is not illegal. Correct. I'm not referring to this. I'm referring to trading on information discerned from communications with e.g. AMD but prior to disclosure of the vulnerability, especially if those communications which establish e.g. timelines are only disclosed after trading Hence my point about trading upon understand…

Generally speaking, a company communicating information to you does not bar you from trading unless you explicitly agree to refrain from making trades.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#302
post #241

Earlier quoted context omitted.

It's quite unsettling that Linus thinks as much of security in general, given that he maintains a kernel and he's responsible for accepting its security modules that are next to unusable because of their complexity. Could his general disbelief lead to a (kind of) dismissive attitude in this respect? Keep in mind he's the one that would never properly disclose of a security fix - instead of saying which problem is fix…

People who work in vulnerability research generally just point and laugh at him. His opinion on this doesn't matter.

And the people who focus on real security point and laugh at the so called "vulnerability research engineers", and agree with Linus point.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#303
post #254

Earlier quoted context omitted.

Pity that vast incentive didn't seem to work out when they promoted all these chips as having "Firmware Trusted Platform Module", "Secure Encrypted Virtualization", "AMD Secure Processor", and "AMD Secure OS" as features. AMDs incentive, like any corporation, is to maximise shareholder value. Same as any tiny little security research firm. If a research firm can maximise their profit buy discovering vulnerabilities a…

CPU's have real value. As to ethics that's mostly irrelevant to this discussion. Both sides could have ethical behavior, I am simply pointing out which side has the larger incentives to exaggerate. After all the stock could drop and a short seller could still lose money. They need the stock to drop a lot even over a minor issue.

While the dollar value of AMDs incentive is without doubt larger - the existential value of the smaller amount incentivising the researcher is likely more motivating...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#304

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

Well, this could be interesting. AMD is a US listed security. If true, these two lads could very look forward to a visit from the US SEC. Seeing as how market manipulation is not a capital-crime, I don't see Australia objecting to an extradition, should charges be warranted.

Which exact crime are you alleging, specifically? Plenty of short sellers investigate companies and their products and make investment decisions based on their findings.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#305
post #254

Earlier quoted context omitted.

CPU's have real value. As to ethics that's mostly irrelevant to this discussion. Both sides could have ethical behavior, I am simply pointing out which side has the larger incentives to exaggerate. After all the stock could drop and a short seller could still lose money. They need the stock to drop a lot even over a minor issue.

While the dollar value of AMDs incentive is without doubt larger - the existential value of the smaller amount incentivising the researcher is likely more motivating...

[deleted]

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#306
post #295

Earlier quoted context omitted.

They're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.

That's true because the vulnerability itself wasn't overblown, and was immediately patched.

I am particularly talking about things like Intel's stock price though

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#307
post #76

Earlier quoted context omitted.

People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…

> I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick So are you talking about AMD being dicks by releasing buggy chips, or the researchers somehow being dicks for finding out? Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the…

[deleted]

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#308
post #306

Earlier quoted context omitted.

That's true because the vulnerability itself wasn't overblown, and was immediately patched.

I am particularly talking about things like Intel's stock price though

Oh. Sure, I buy that. I don't believe patchable vulnerabilities really exert major pressure on stock prices.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#309

Earlier quoted context omitted.

Well, this could be interesting. AMD is a US listed security. If true, these two lads could very look forward to a visit from the US SEC. Seeing as how market manipulation is not a capital-crime, I don't see Australia objecting to an extradition, should charges be warranted.

Which exact crime are you alleging, specifically? Plenty of short sellers investigate companies and their products and make investment decisions based on their findings.

They tend not to weaponize those findings putting innocent people in harms way.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#310
post #76

Earlier quoted context omitted.

People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…

> I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick So are you talking about AMD being dicks by releasing buggy chips, or the researchers somehow being dicks for finding out? Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the…

> Related question: if a "food security researcher" discovered a vendor was selling contaminated produce - would it be reasonable for them to give the vendor 90 days notice before telling the public?

This example is absolutely farcical. It's not even close to the same thing and you know it. A security flaw is not equivalent to poisoned food - it still requires outside action to be exploited.

Post reply on HN