Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

341–350 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#341

Earlier quoted context omitted.

Matt Levine wrote about this recently, and comes to a somewhat different conclusion (though he's not a lawyer): https://www.bloomberg.com/view/articles/2018-02-09/can-noisy... > If you think a company is bad, or fraudulent, you can sell its stock short and try to profit when everyone discovers its problems and the stock drops. If you want to hurry that process along, you can always noisily publish research reports ex…

But he more or less assumes that you are stating an opinion on the company, rather than misrepresenting or downright inventing bad news.

True, that's the actual crux of the question here; if you are inventing bad news and trading on it, then by my reading you're probably engaging in stock manipulation.

On the other hand, it seems that uncovering new true information, and then taking a short position on it, not illegal.

A lot of the comments in this thread were assuming that there was some crime just from reporting the bad news and trading on it, unconditionally on whether or not the news was true.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#342
post #302

Earlier quoted context omitted.

People who work in vulnerability research generally just point and laugh at him. His opinion on this doesn't matter.

And the people who focus on real security point and laugh at the so called "vulnerability research engineers", and agree with Linus point.

No, that isn’t a thing

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#343

Earlier quoted context omitted.

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…

I agree, but I am curious if you have any suggestions on how we should be handling disclosure?

For what it’s worth, this is a fierce debate that goes back decades. There is widespread disagreement among professionals in the field.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#344
post #316

Earlier quoted context omitted.

Obviously, yes. Your "some portion of" should read "virtually all". I answered your question. But you didn't answer my question. What about the flaws that aren't unintuitive? What about the bog standard integer overflows vendors routinely leave in code because they won't pay what it costs to ensure they don't ship them?

How does that matter? The only thing that matters is the harm that certain types of disclosures will do to average users. It doesn't matter whether a bug could have easily been found before release or not; the bug is there, in the wild, in a position to harm users. By all means, vendors should be taken to task, and be beaten up even more when a bug was easily avoidable. But a bug's stupidity is completely unrelated t…

> The only thing that matters is the harm that certain types of disclosures will do to average users

I disagree. This does not account for the fact that malicious actors are likely to exploit these before the vendor fixes them on a schedule that they would prefer to dictate. And all users are not incapable of making alternative judgments about the use of vulnerable technology. Users include my Mom, hackers at small companies, giant corporations who are capable of overnight turning off SMB V1.

The harm to users comes from vulnerable software that the vendors put there in the first place.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#345
post #140

Earlier quoted context omitted.

More and more lately I'm leaning towards the, "responsible disclosure is a bunch of crap" camp. You have to be "in" to get the news. Even if you're "in" security people love to play info war power games and withhold things because it tickles their jimmies, etc. And don't forget, you're deliberately keeping a vulnerability secret from consumers during a long period where you have no idea who else knows about it. If I'…

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security. It's sad…

> It's sad to see people arguing for a return to those norms

Where do you see anyone arguing for that? Or is it just a strawman? What I see is not people arguing against disclosure but people arguing for disclosure with an embargo longer than a day. You're going to have a hard time proving that one day is a norm, or that it correlates with a renaissance in securing software. Your response looks much more like circling the wagons when a member of your tribe is criticized.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#346
post #91
post #77

Earlier quoted context omitted.

What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html

Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%2...

Let's use "coordinated disclosure" then - that is generally considered the preferred method these days.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#347

Earlier quoted context omitted.

No need for the attitude. Just take a look on twitter at what prominent members of the community are saying - they are not impressed with this behaviour. I'm also a member of that community, and hold the same view. The vast majority of the infosec community promote coordinated disclosure.

If you're referring to vulnerability research twitter, and not, I don't know, IT security twitter, then no that's not what's happening. The CTS-Labs people are taking shit from vulnerability research twitter for overhyping the findings (meaning: they released a report on a day ending in "y"). People are noting the connection to the short selling --- but since this will be the 3rd or 4th time someone has very publicly…

I somehow sense you have already made up your mind about the ethics of this, have your own - rather fixed - views of what the majority of researchers think of it, and are unwilling to listen to opposing arguments. I'll stop trying.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#348

Earlier quoted context omitted.

Well, this could be interesting. AMD is a US listed security. If true, these two lads could very look forward to a visit from the US SEC. Seeing as how market manipulation is not a capital-crime, I don't see Australia objecting to an extradition, should charges be warranted.

Which exact crime are you alleging, specifically? Plenty of short sellers investigate companies and their products and make investment decisions based on their findings.

I work in finance, and one of the many hats I wear at the small ATS (Alternative Trading System) I work at is regulatory analyst. Action probably wont start with SEC, but possibly FINRA or any exchange they're trading through. This definitely wreaks of manipulation. If I knew of any trades on this came through my ATS, it would be my legal and ethical duty to report it. I could still be asked to provide all trade activity for AMD.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#349

Earlier quoted context omitted.

> Trading on non-public information that results from your own research and then announcing it is not illegal. Correct. I'm not referring to this. I'm referring to trading on information discerned from communications with e.g. AMD but prior to disclosure of the vulnerability, especially if those communications which establish e.g. timelines are only disclosed after trading Hence my point about trading upon understand…

Generally speaking, a company communicating information to you does not bar you from trading unless you explicitly agree to refrain from making trades.

This is fair. Thanks.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#350
post #150
post #136

Earlier quoted context omitted.

black hats use them for bad, white hats use them for good. ideological discussions about disclosure policy aside, if they are doing this to manipulate stock prices and in doing so create a situation where more actual exploits occur, I'd say that is 'black hat' behavior.. the 'weaponization' is in the 'social engineering' of the market reaction, rather than a direct exploit in this case..

The problem with your first line is that it leaves the definition of black hat open to interpretation, when that is not how the word is actually used in the security industry or in popular reporting. Black hat activity specifically refers to criminal activity, which we can demonstrably perceive and attribute. By your reasoning, I am free to call security researchers black hats if they don't give vendors advance notic…

> Black hat activity specifically refers to criminal activity, which we can demonstrably perceive and attribute

stock manipulation is clearly criminal, if you want to take the 'letter of the law' approach..

beyond this, this gets into the same debate as letter of the law vs spirit of the law, which has both nothing and everything to do with this topic.. black hat is not 'defined exclusively' anywhere, and of course one leaning to a 'letter of the law' argument would then also look for 'exclusive definitions'

as to your point:

> free to call security researchers black hats if they don't give vendors advance notice.

if they are doing this for malicious purposes, yes

if it is for an ideological stance, then, well, it depends on how you view their ideology.

what happens if the law is incorrect?

again, letter of the law vs spirit of the law.

"normative argument about whether or not something is ultimately unethical"

laws are normative arguments about whether or not something is ultimately unethical.. not neutral 'things' that exist in a vacuum. and they can be correct or incorrect, and also incompletely defined..

how does acting completely unethically yet entirely within the law for malicious purposes fit into your framework?

Say for example, actively portscanning (legality nebulous) for already infected computers and then overcharging 2000% for cleanup? Then spamming virii from a jurisdiction where it is not illegal in order to grow this 'business'? All legal.. so it's "white hat?" or is it 'grey hat' because it is in a legal 'gray area'? I don't think that's what grey hat means either..

Post reply on HN