Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

61–70 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#61
post #38
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

Go fuck yourself.

There are plenty of ways to be outraged by the actions of these "independent reseachers." How about 1. Irresponsible disclosure affecting end users. 2. Shady trading practices of their hedge fund CFO. Just to name 2.

You are a fucking retard, and your obvious anti-AMD bias is showing.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#62
post #2

>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…

> 1-day notice? Such aggressive wording without even the chance for AMD to address the concerns?

Are the reporting parties under any obligation to give AMD notice?

Behaving according to AMD's wishes is not an obligation. Businesses will be the first to tell you that agreements and laws form obligations, not what someone perceives as a nice thing to do.

If not, then you're reacting to a distraction, a detail that doesn't matter: how the corporate-friendly tech press is trying to shift blame away from the party that either sold CPUs with bugs in them (mistakes happen, and this is unfortunate) or distributed nonfree (proprietary, user-subjugating) software which also happens to contain insecurities (a malicious and unjust way to distribute software).

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#63
post #32

Earlier quoted context omitted.

Have you done a lot of published security research?

Nice non-sequitur. Somehow the limiting factor on the ability of someone to judge professionalism is the number of papers they've written?

No, I'm just noticing again that people who don't don't do a lot of vulnerability research have a lot of interesting opinions about the professional norms of people who do that work. But you never know --- maybe they do a lot of research, in which case, yes, their opinion on security research norms is a lot more interesting to me.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#64
post #58
post #21

Earlier quoted context omitted.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

He did say “should” disqualify someone from employment, which I read as “ought to.” Idealism maybe. But with black or gray hat research, you’re right.

No, disclosing vulnerabilities without disclosure does not in fact make you a "grey hat", much as vendors would like that to be so.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#65
post #21

24hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

It's not unheard of in the sense of never having happened, but it is a clear breach of ethics for a security researcher. (The term for not doing what these guys did is "responsible disclosure").

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#66
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

Mentioned in another comment, but from their management page: http://www.cts-labs.com/management-team > He [Yaron, CFO] is also the founder and Managing Director of NineWells Capital, a hedge fund that invests in public equities internationally. I wonder how linked the companies are - is this basically a vulnerability research company as a research arm of a hedge fund?

It sure seems that way. It wouldn't be the first; look, for instance, at Justine Bone's MedSec.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#67
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

Is this kind of language common in other security disclosures?

No, this is a first. Even MedSec was more coy than this.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#70
post #21

Earlier quoted context omitted.

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research. "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

It's not unheard of in the sense of never having happened, but it is a clear breach of ethics for a security researcher. (The term for not doing what these guys did is "responsible disclosure").

If you put 10 people who find and publish security vulnerabilities professionally in a room, I do not think you would secure agreement that this is a "clear breach of ethics". There are extremely well-known researchers who have made a point of not coordinating with vendors; vendors, historically, have been far more abusive than researchers.
Post reply on HN