Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

311–320 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#311
post #7
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

Yeah it's suspicious. The website[1] has many fancy infographics, marketable names and fear mongering but you have to dig into the whitepaper[2] to find any details about the actual vulnerabilities. And even then it starts only on page 8 of 20 and you discover that it's vulnerabilities targeting the secure boot infrastructure and you need local admin to exploit them. It's not good but it's not a new Spectre or Meltdo…

I tend to imagine that if Intel were doing this they’d do a better job of it. Even if CTS-Labs are completely legit, the way it’s been done has led to immediate suspicion of the claims and people involved, in a way that feels much more like a small group straining for attention or to make a quick buck and making a bit of a mess of it. If Intel were involved, I’d expect it to be done more professionally and simply better, so that people don’t suspect foul play and go looking for problems. It is possible for a company to deliberately obfuscate the trail by doing it this way, at the probable cost of some effectiveness (though if the claims are overblown it might perhaps be more effective this way), but it seems less likely.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#312
post #248

Earlier quoted context omitted.

>Right, and neither did these researchers. I'm just going to conclude that you are trolling at this point and try to forget this headache of a thread.

Actually dsacco convinced me with his arguments (that those guys are not black hats). Don't assume bad faith in opponents when you are losing the argument ... On the other hand I agree with responsible disclosure. And I think that should be made mandatory by law. And finally, I also agree with some fines for companies allowing these holes to exist for so long. Especially those discoverable by 4 (more or less) random…

The video was on a green screen, the background was all stock images.

These guys are not professional at all.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#313
post #295

Earlier quoted context omitted.

Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.

They're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.

Attacks only get better.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#314
post #257

Earlier quoted context omitted.

> and then telling you about it? The argument against your position that people are trying to get across to you is not that. It is that publication of vulnerability without giving heads-up and time to prepare solution to the vendor greatly increases the risk that a user will be harmed by attackers exploiting the public knowledge. Often substantial number of users are not going to mitigate or resolve the problem witho…

And if I don't want to jump through whatever random hoops message board nerds have erected and just decide not to disclose at all, exactly how are you better off?

I don't think anyone's arguing that a researcher has a responsibility to tell anyone. If they find a vulnerability and then decide to completely shelve it, that's fine (if maybe a little pointless?). But if they do decide to do some kind of disclosure, I (and others) would argue that researchers have an ethical responsibility to do so in a way that they believe will do the least harm.

It's certainly reasonable to argue which kind of disclosure is the best way to achieve minimal harm, but my opinion is that it's unethical to disclose without considering what method of disclosure will do the least harm, or, worse, just not caring and going for the "biggest splash", as is what it seems these researchers did.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#315

Earlier quoted context omitted.

”The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws.” I know everyone in my family is ignorant of this “disclosed” security flaw and is powerless to mitigate the vulnerabilities disclosed on their own. Even if they did know to “turn off their computer” as someone said, are they supposed to wait until someone calls them to tell them a patch…

How many vulnerabilities are you capable of finding in software that everyone in your family uses, and can't find for themselves? I'm sure the number is not zero. Is it unethical for you not to go look for them?

Looking is fine. Disclosing in a way that's likely to cause harm that could otherwise be minimized with a little care... not so much.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#316
post #267

Earlier quoted context omitted.

So let me get this straight: are you arguing that because some portion of bugs each year is due to vendor negligence, it is OK for us security researchers to make the vulnerabilities public and expose users dependent on the vendor any time we want?

Obviously, yes. Your "some portion of" should read "virtually all". I answered your question. But you didn't answer my question. What about the flaws that aren't unintuitive? What about the bog standard integer overflows vendors routinely leave in code because they won't pay what it costs to ensure they don't ship them?

How does that matter? The only thing that matters is the harm that certain types of disclosures will do to average users. It doesn't matter whether a bug could have easily been found before release or not; the bug is there, in the wild, in a position to harm users.

By all means, vendors should be taken to task, and be beaten up even more when a bug was easily avoidable. But a bug's stupidity is completely unrelated to how a user might be harmed by an "irresponsible" disclosure. Giving the vendor their just desserts is secondary to that.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#317
post #91
post #77

Earlier quoted context omitted.

What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html

Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...

BTW, one of the twitter threads went into their disclosure philosophy.

https://twitter.com/gadievron/status/973655683269873664

It turns out it's exactly the "release a general idea to the public to light a fire under the vendor's ass, only release exact technical details to the people who need to know" that you might expect. They didn't dump a zero-day into public.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#318

Earlier quoted context omitted.

Which exact crime are you alleging, specifically? Plenty of short sellers investigate companies and their products and make investment decisions based on their findings.

They tend not to weaponize those findings putting innocent people in harms way.

Perhaps so, but that's not a crime. There's nothing illegal about trading on your own private research.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#319

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

If you look at the metadata of both the white paper and the analysis, you can see that the creation time of them is only 2 hours, 50 minutes apart. And that's the creation date, not even when they were published. https://pastebin.com/CcDTz0hB

(Replying to myself because I can't edit my post anymore)

Edit: And it gets better! If you check the HTTP headers when requesting the whitepaper from their servers, it will tell you that the file was placed there (last-modified) at 13:22 GMT, so just 1 hour before Viceroy Research Group created their analysis - and probably ages before the actual news broke.

https://pastebin.com/gXVd9cff

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#320
post #318

Earlier quoted context omitted.

They tend not to weaponize those findings putting innocent people in harms way.

Perhaps so, but that's not a crime. There's nothing illegal about trading on your own private research.

Trading on research, no. But attempting to artificially manipulate the market while doing so is effectively "pump-and-dump" but short instead of long. A lot comes down to timing and exactly what the communication says.

Not a sure-thing conviction, but certainly a dangerous business plan.

Post reply on HN