Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

351–359 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#351
post #350
post #150

Earlier quoted context omitted.

The problem with your first line is that it leaves the definition of black hat open to interpretation, when that is not how the word is actually used in the security industry or in popular reporting. Black hat activity specifically refers to criminal activity, which we can demonstrably perceive and attribute. By your reasoning, I am free to call security researchers black hats if they don't give vendors advance notic…

> Black hat activity specifically refers to criminal activity, which we can demonstrably perceive and attribute stock manipulation is clearly criminal, if you want to take the 'letter of the law' approach.. beyond this, this gets into the same debate as letter of the law vs spirit of the law, which has both nothing and everything to do with this topic.. black hat is not 'defined exclusively' anywhere, and of course o…

> laws are normative arguments about whether or not something is ultimately unethical

That wasn't the distinction I was making. A law is a positive statement. An argument of what should be lawful, or an interpretation of a law, is of course normative. But I already said that in this thread.

By the "letter of the law" (section 9(4)(a) of the SEC act and existing case law), stock manipulation involves promulgating outright falsehoods. Case law shows us that exemplary falsehoods have to be categorically untrue; a biased presentation of something that is true does not pass the bar. Being that there is a vulnerability here, the material we have to go on does not paint a favorable outlook on the researchers being indicted. Activist investors routinely present facts to the media with a clear agenda, but the SEC virtually never prosecutes them if there is an inarguable, material kernel of truth to their allegations. There's a vulnerability here. Reasonable people can disagree on the severity of the vulnerability and how it should have been disclosed. But it's not fraud.

> how does acting completely unethically yet entirely within the law for malicious purposes fit into your framework?

Your question has a presupposition; if the security researchers traded on their knowledge of this vulnerability, I find that to be neither unethical nor illegal stock manipulation.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#352

Earlier quoted context omitted.

I think saying that they were outdone by 4 dudes in a basement is being intellectually dishonest. There are a lot of dudes in a lot of basements looking for vulnerabilities all the time. Those four happened to find it, but there were hundreds of others looking. There’s no amount of money that amd can spend that would make them not outgunned eventually by all the hackers and intelligence services and security research…

Why do you assume that there were hundreds of other people looking for these vulnerabilities? Chances are, when we learn the technical details, we're going to find out that they're bog-standard memory corruption flaws in driver code, and that the thing that prevented anyone from discovering them was that nobody looked for them .

You honesty think nobody was looking for security vulnerabilities?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#353

Earlier quoted context omitted.

I tend to imagine that if Intel were doing this they’d do a better job of it. Even if CTS-Labs are completely legit, the way it’s been done has led to immediate suspicion of the claims and people involved, in a way that feels much more like a small group straining for attention or to make a quick buck and making a bit of a mess of it. If Intel were involved, I’d expect it to be done more professionally and simply bet…

A really fun interpretation of it is AMD doing it themselves, deliberately badly, so that they can come off as the wounded party that actually have really good hardware. Risky, but probably not impossible to carry off.

While fun, it would also mean they would be publicly disclosing vulnerabilities in their own systems and then deliberately withholding the patch, just to put on this shpiel in order to appear as the underdog?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#354
post #38
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

How about

3. The vulnerabilities are real, and something smells real fishy about the way they were released, including what appears to be 4 dudes in a basement.

Except that's not necessarily something to get "outraged" about, just something to keep an eye on while this story develops.

The only one I see shouting "this is an outrage!" appears to .. be made of .. straw?

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#355
post #93

Earlier quoted context omitted.

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that. They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets. Security res…

I strongly disagree with the reasoning you're using here. The premise of your argument is that without vendor cooperation, end-users are helpless to mitigate the impact of security flaws. No, they aren't. Not only are they not helpless, but many of them are in fact ethically obligated to mitigate exposures with or without the assistance of their vendors. Almost every end user has at least one last-resort mitigation f…

> If there was working Usenet search in 2018, you could find me making approximately the same argument back in the 1990s, when I worked as a researcher at SNI, the world's first commercial vulnerability research lab.

This being a controversial topic straight at the intersection of technology, the way it changed and affected society, the public good and our dependence on technology, I really don't think that "I haven't changed my mind about this in 28 years" supports your argument ...

And honestly I would say that whether I agree or not.

I wasn't working in security but I definitely moved my opinion on the matter. In the (late) 90s I was mostly for full public disclosure arguing the same "we're better off when we have the most information available to us". But today I'm leaning way more towards "responsible disclosure is good" (as you can tell I'm also not 100% black-and-white on the matter like you said you are).

Maybe it's because I was younger then and had more of a reckless mentality and an innocent belief that people will make the right choices given enough information.

Maybe it's because in the past 28 years technology has changed our society to such an extent that impact of security vulnerabilities is rather incomparable to the impact they had back then.

Maybe it's because I definitely don't believe that you can defend this opinion with the very same arguments that were used back then without even addressing the spread of information technology and the drastic way they altered society in the past 28 years.

Maybe it's because I now realise that I myself am not always better off with more information if I can't act on it, and therefore it's not reasonable to assume it as a general rule. Which is very much something I had yet to learn 28 years ago, had to swallow some pride. I wish everybody was a clever as I was back then ...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#356
post #204

Earlier quoted context omitted.

> These vulnerabilities are all post-compromise privilege escalation flaws I would say they are all invasive evil maid threat vectors. Each one requires either physical access to the hardware or (as you stated) an already established root privileges. We all know that if you have physical access to hardware, it's essentially game over. However . One of the vulnerabilities supposedly allowed to subvert UEFI secure boot…

While I'm fine with criticizing them for partial disclosure, I again have a problem mapping any of this back to ethics, because, again, independent researchers do not have an obligation to vendors or to any amorphous public. As long as they aren't literally exploiting (or arranging to have exploited) vulnerabilities to break into people's computers, or lying about what they found, I don't think ethics have much to sa…

> I don't think ethics have much to say about what they should do.

What does that even mean? What do you think "ethics" means? This is a nonsensical statement.

The consideration of what people in certain situations should or should not do, IS ethics.

Even if someone would say (for some reason) "but researchers should be able to do their work without consideration", that is making an ethical statement.

I understand why you would have a problem mapping this back to ethics, because if you'd formulate it as such, it would sound kind of bad: Researchers have no ethical responsibilities to the public.

You can't choose to not let decisions be guided by ethics, that's like claiming you choose to find your way without navigating. It makes no sense.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#357
post #351
post #350

Earlier quoted context omitted.

> Black hat activity specifically refers to criminal activity, which we can demonstrably perceive and attribute stock manipulation is clearly criminal, if you want to take the 'letter of the law' approach.. beyond this, this gets into the same debate as letter of the law vs spirit of the law, which has both nothing and everything to do with this topic.. black hat is not 'defined exclusively' anywhere, and of course o…

> laws are normative arguments about whether or not something is ultimately unethical That wasn't the distinction I was making. A law is a positive statement. An argument of what should be lawful, or an interpretation of a law, is of course normative. But I already said that in this thread. By the "letter of the law" (section 9(4)(a) of the SEC act and existing case law), stock manipulation involves promulgating outr…

> Your question has a presupposition

that it is specifically tied to this case.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#358

Earlier quoted context omitted.

A really fun interpretation of it is AMD doing it themselves, deliberately badly, so that they can come off as the wounded party that actually have really good hardware. Risky, but probably not impossible to carry off.

While fun, it would also mean they would be publicly disclosing vulnerabilities in their own systems and then deliberately withholding the patch, just to put on this shpiel in order to appear as the underdog?

Confirmation that the vulnerabilities are legitimate pretty much writes this one off. At the time I wrote it this wasn’t entirely clear, though it seemed probable (though even then they could have been overstated).

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#359

Earlier quoted context omitted.

Why do you assume that there were hundreds of other people looking for these vulnerabilities? Chances are, when we learn the technical details, we're going to find out that they're bog-standard memory corruption flaws in driver code, and that the thing that prevented anyone from discovering them was that nobody looked for them .

You honesty think nobody was looking for security vulnerabilities?

In drivers for an AMD security feature almost nobody uses? Yes.
Post reply on HN