Live data from Hacker News

The RCE that AMD won't fix

mrbruh.com

61–70 of 182 posts

Re: The RCE that AMD won't fix

#61
post #39

AMD AutoUpdate terminal always pops up at midnight for me and then requires me to dismiss it. I've been meaning to uninstall this but always forget about it the next morning. Now I have good reason to block it entirely and go back to manual updates

Omg that's what it is. I've been looking for DAYS.

Re: The RCE that AMD won't fix

#62

> This means that a malicious attacker on your network, or a nation state that has access to your ISP can easily perform a MITM attack and replace the network response with any malicious executable of their choosing. I am pretty sure, a nation state wanting to hack an individual's system has way more effective tools at their disposal.

...such as talking directly to AMD or even Microsoft, which is scarier as Windows Updates are signed, and as long as they can be convinced to sign the right thing, it'll look even more legit.

Re: The RCE that AMD won't fix

#63
post #3

This is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right? I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediat…

> Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediately own anyone with ATI graphics?

Some of us do not enable automatic updates (automatic updates are the peak of stupidity since Win98 era). And, when you sit in an airport, you don't update all your programs.

Re: The RCE that AMD won't fix

#64
How the hell is it possible that they're still using the ATI domain and HTTP 2026? They acquired ATI 20 fucking years ago.

It really makes you wonder what level of dysfunction is actually possible inside a company. 30k employees and they can't get one of them to hook up certbot, and add an 's' to the software.

Re: The RCE that AMD won't fix

#65
post #3

This is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right? I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediat…

Who would connect to unknown person's hotspot?

But it seems pretty trivial for some bad actor at local ISP.

Re: The RCE that AMD won't fix

#66

Many people don't worry about connecting to random wifi anymore, but users of AMD still have to

I do usually worry - because DNS spoofing is still possible and we are one step (eg: a compromised certificate) away from being pwned. But yeah one shouldn't have to worry.

Re: The RCE that AMD won't fix

#69
post #3

This is super bad right? Like anybody who has this running will be vulnerable to a super basic HTTP redirect -> installer running on their machine attack, right? And on top of that it's for something that is likely installed on _so many_ machines, right? I don't think I've ever seen something this exploitable that is so prevalent. Like couldn't you just sit in an airport and open up a wifi hotspot and almost immediat…

Who would connect to unknown person's hotspot? But it seems pretty trivial for some bad actor at local ISP.

This is oh sweet summer child stuff.

Have you ever gone to a crowded public place and setup an open hotspot?

Re: The RCE that AMD won't fix

#70

Earlier quoted context omitted.

Who would connect to unknown person's hotspot? But it seems pretty trivial for some bad actor at local ISP.

This is oh sweet summer child stuff. Have you ever gone to a crowded public place and setup an open hotspot?

Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.
Post reply on HN