Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

321–330 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#321
post #318

Earlier quoted context omitted.

Perhaps so, but that's not a crime. There's nothing illegal about trading on your own private research.

Trading on research, no. But attempting to artificially manipulate the market while doing so is effectively "pump-and-dump" but short instead of long. A lot comes down to timing and exactly what the communication says. Not a sure-thing conviction, but certainly a dangerous business plan.

Apparently known as "short and distort". See also "When Does Short Selling Become Manipulation?":

http://www.klgates.com/files/tempFiles/901e34d6-b3ee-4ac4-bd...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#322
post #318

Earlier quoted context omitted.

Perhaps so, but that's not a crime. There's nothing illegal about trading on your own private research.

Trading on research, no. But attempting to artificially manipulate the market while doing so is effectively "pump-and-dump" but short instead of long. A lot comes down to timing and exactly what the communication says. Not a sure-thing conviction, but certainly a dangerous business plan.

Matt Levine wrote about this recently, and comes to a somewhat different conclusion (though he's not a lawyer):

https://www.bloomberg.com/view/articles/2018-02-09/can-noisy...

> If you think a company is bad, or fraudulent, you can sell its stock short and try to profit when everyone discovers its problems and the stock drops. If you want to hurry that process along, you can always noisily publish research reports explaining why the company is bad or fraudulent. If your research reports convince other investors of your thesis, then the stock will drop, and you will make money. There are more longs than shorts, and more dicey public companies than noisy short hedge funds, and so people who use this strategy tend not to be especially popular. In particular people often go around accusing them of fraud, or market manipulation. "Wait," people ask, "how is it not manipulation to short a stock and then publicly announce that the stock is bad?" I am always confused by this complaint. Just flip it around: It's not manipulation, surely, to own a stock and then publicly announce that the stock is good.

(Followed by further justification of this position).

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#323
post #321

Earlier quoted context omitted.

Trading on research, no. But attempting to artificially manipulate the market while doing so is effectively "pump-and-dump" but short instead of long. A lot comes down to timing and exactly what the communication says. Not a sure-thing conviction, but certainly a dangerous business plan.

Apparently known as "short and distort". See also "When Does Short Selling Become Manipulation?": http://www.klgates.com/files/tempFiles/901e34d6-b3ee-4ac4-bd...

From that paper, 'The term “manipulative... connotes intentional or willful conduct designed to deceive or defraud investors by controlling or artificially affecting the price of securities."

If the claims you're making are true, then it's not deceiving or defrauding, even if the way the information was published was immoral under standard professional ethics.

If these vulnerabilities were misrepresented by the short sellers that funded it, then I suspect that would bring them into stock manipulation territory.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#324

Earlier quoted context omitted.

Have you ever worked with a code base before? Even when you scrutinize for bugs, they still can go unspotted. Sometimes hundreds of people can look at the same code and not see anything wrong with it. Software has the benefit of having higher levels of abstraction, I haven't designed any hardware but as far as I'm aware it's not easy to abstract it. That will make it much harder to find things. While 4 guys in a base…

I've been a professional software developer since 1995.

You should really say ‘94 instead.

http://www.cc.com/video-clips/cio5rg/chappelle-s-show-tupac-...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#325

Earlier quoted context omitted.

> about AMD being dicks by releasing buggy chips Everybody releasing chips releases buggy chips. It's the current reality of both hardware and software. Unless they do it maliciously, they're not dicks.

Does everyone who releases drivers release buggy drivers?

What's important aren't really the bugs, bugs can be fixed. What's important is who is allowed to run, inspect, share, and modify the code. If only the copyright holder is allowed to do this, that's proprietary software and that's malicious. If a user's software freedom is respected so users can choose to fix it themselves, wait for another release, hire someone else to fix the code, or live with the bugs that's treating the user properly.

Everyone makes mistakes; it's more about how those mistakes are handled and if a user's control over their computer is respected.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#326
post #112
post #74

Earlier quoted context omitted.

> Could something like this be considered inside information? No, illegal insider trading refers to trading on inside information when you have a confidentiality agreement or a fiduciary duty. Information asymmetry is insufficient (or else it would be virtually impossible to profitably trade at all). > Or is it legal to actively manipulate stock prices to ones benefit in this way? The way you're presenting this is a…

Might the latter also depend on how you present it? As far as I can see this is only an exploit of secure boot if you are already on ring 0 level auth. Making a whole webpage with lots of graphics and whatnot, sending press releases all over and in general present it like a security flaw on the level of meltdown seems .. false? Probably court level material.. In any case it seems to have backfired as the stock is up.

Hopefully someone with more experience can answer this, but could the stock be going up due to high short interest?

Maybe not technically a short squeeze (https://en.m.wikipedia.org/wiki/Short_squeeze) but related?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#327

Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations. Headline: >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Viceroy Research lists no employees or contact address, but it appea…

Why is AMD 1.04% up today then (while technology index is -1.16%)? https://finance.google.com/finance?q=amd AMD $11.64

Look at the interday pricing. There were some small slumps. Clearly most traders did not react too negatively to the story, at least by the end of the day.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#328
post #77
post #38

Earlier quoted context omitted.

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html

> What about responsible disclosure ethics?

"Responsible" to whom? Terms like these indicate what side one takes, such as how one expands the term "DRM": digital rights management means taking the 1%/elite side favored by the publisher, the few in power. 'Digital restrictions management' highlights what's happening from the user's side, the 99%, the side of the many. Similarly with the harm to the users and the desire for freedom in the term "jailbreaking".

So, since we recognize the reporters owe AMD nothing, to whom are they "responsible"? Or what are they responsible for?

This phrase strikes me as useless except to try to foist a responsibility on people that they don't actually have and getting the relatively powerless to serve the interests of power -- users who can't inspect, edit, or share edited CPU microcode are somehow not acting responsibly if they don't give proprietors sufficient notice.

Where is the "responsible disclosure" for Intel when they refuse to let users fully control the signing keys used in the software that sees every network packet before the rest of the computer (for inbound network traffic) and before a packet leaves the computer (for outbound traffic)? The one-sidedness of it all sticks out like a sore thumb.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#329
post #7

Earlier quoted context omitted.

Yeah it's suspicious. The website[1] has many fancy infographics, marketable names and fear mongering but you have to dig into the whitepaper[2] to find any details about the actual vulnerabilities. And even then it starts only on page 8 of 20 and you discover that it's vulnerabilities targeting the secure boot infrastructure and you need local admin to exploit them. It's not good but it's not a new Spectre or Meltdo…

I tend to imagine that if Intel were doing this they’d do a better job of it. Even if CTS-Labs are completely legit, the way it’s been done has led to immediate suspicion of the claims and people involved, in a way that feels much more like a small group straining for attention or to make a quick buck and making a bit of a mess of it. If Intel were involved, I’d expect it to be done more professionally and simply bet…

A really fun interpretation of it is AMD doing it themselves, deliberately badly, so that they can come off as the wounded party that actually have really good hardware. Risky, but probably not impossible to carry off.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#330

Earlier quoted context omitted.

Trading on research, no. But attempting to artificially manipulate the market while doing so is effectively "pump-and-dump" but short instead of long. A lot comes down to timing and exactly what the communication says. Not a sure-thing conviction, but certainly a dangerous business plan.

Matt Levine wrote about this recently, and comes to a somewhat different conclusion (though he's not a lawyer): https://www.bloomberg.com/view/articles/2018-02-09/can-noisy... > If you think a company is bad, or fraudulent, you can sell its stock short and try to profit when everyone discovers its problems and the stock drops. If you want to hurry that process along, you can always noisily publish research reports ex…

But he more or less assumes that you are stating an opinion on the company, rather than misrepresenting or downright inventing bad news.
Post reply on HN