>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…
Yeah it's suspicious. The website[1] has many fancy infographics, marketable names and fear mongering but you have to dig into the whitepaper[2] to find any details about the actual vulnerabilities. And even then it starts only on page 8 of 20 and you discover that it's vulnerabilities targeting the secure boot infrastructure and you need local admin to exploit them. It's not good but it's not a new Spectre or Meltdo…
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
311–320 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#312Earlier quoted context omitted.
>Right, and neither did these researchers. I'm just going to conclude that you are trolling at this point and try to forget this headache of a thread.
Actually dsacco convinced me with his arguments (that those guys are not black hats). Don't assume bad faith in opponents when you are losing the argument ... On the other hand I agree with responsible disclosure. And I think that should be made mandatory by law. And finally, I also agree with some fines for companies allowing these holes to exist for so long. Especially those discoverable by 4 (more or less) random…
These guys are not professional at all.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#313Earlier quoted context omitted.
Then you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.
They're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#314Earlier quoted context omitted.
> and then telling you about it? The argument against your position that people are trying to get across to you is not that. It is that publication of vulnerability without giving heads-up and time to prepare solution to the vendor greatly increases the risk that a user will be harmed by attackers exploiting the public knowledge. Often substantial number of users are not going to mitigate or resolve the problem witho…
And if I don't want to jump through whatever random hoops message board nerds have erected and just decide not to disclose at all, exactly how are you better off?
It's certainly reasonable to argue which kind of disclosure is the best way to achieve minimal harm, but my opinion is that it's unethical to disclose without considering what method of disclosure will do the least harm, or, worse, just not caring and going for the "biggest splash", as is what it seems these researchers did.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#315Earlier quoted context omitted.
”The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws.” I know everyone in my family is ignorant of this “disclosed” security flaw and is powerless to mitigate the vulnerabilities disclosed on their own. Even if they did know to “turn off their computer” as someone said, are they supposed to wait until someone calls them to tell them a patch…
How many vulnerabilities are you capable of finding in software that everyone in your family uses, and can't find for themselves? I'm sure the number is not zero. Is it unethical for you not to go look for them?
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#316Earlier quoted context omitted.
So let me get this straight: are you arguing that because some portion of bugs each year is due to vendor negligence, it is OK for us security researchers to make the vulnerabilities public and expose users dependent on the vendor any time we want?
Obviously, yes. Your "some portion of" should read "virtually all". I answered your question. But you didn't answer my question. What about the flaws that aren't unintuitive? What about the bog standard integer overflows vendors routinely leave in code because they won't pay what it costs to ensure they don't ship them?
By all means, vendors should be taken to task, and be beaten up even more when a bug was easily avoidable. But a bug's stupidity is completely unrelated to how a user might be harmed by an "irresponsible" disclosure. Giving the vendor their just desserts is secondary to that.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#317Earlier quoted context omitted.
What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html
Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...
https://twitter.com/gadievron/status/973655683269873664
It turns out it's exactly the "release a general idea to the public to light a fire under the vendor's ass, only release exact technical details to the people who need to know" that you might expect. They didn't dump a zero-day into public.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#318Earlier quoted context omitted.
Which exact crime are you alleging, specifically? Plenty of short sellers investigate companies and their products and make investment decisions based on their findings.
They tend not to weaponize those findings putting innocent people in harms way.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#319Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…
If you look at the metadata of both the white paper and the analysis, you can see that the creation time of them is only 2 hours, 50 minutes apart. And that's the creation date, not even when they were published. https://pastebin.com/CcDTz0hB
Edit: And it gets better! If you check the HTTP headers when requesting the whitepaper from their servers, it will tell you that the file was placed there (last-modified) at 13:22 GMT, so just 1 hour before Viceroy Research Group created their analysis - and probably ages before the actual news broke.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#320Earlier quoted context omitted.
They tend not to weaponize those findings putting innocent people in harms way.
Perhaps so, but that's not a crime. There's nothing illegal about trading on your own private research.
Not a sure-thing conviction, but certainly a dangerous business plan.