Earlier quoted context omitted.
Seeing as CTS-Lab's CFO also founded a hedge fund you're probably on the right track. >Yaron co-founded CTS-Labs in 2017, and previously served as an intelligence analyst in the Israeli Intelligence Corps Unit 8200. He is also the founder and Managing Director of NineWells Capital, a hedge fund that invests in public equities internationally. He holds a B.A. and M.A. from Yale University.
Basically a follow the money situation. Could something like this be considered inside information? Or is it legal to actively manipulate stock prices to ones benefit in this way?
Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
81–90 of 359 posts
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#82"RYZENFALL allows malicious code to take complete control over the AMD Secure Processor."
"Multiple vulnerabilities in AMD Secure Processor firmware allow attackers to infiltrate the Secure Processor."
If this is legitimate, this is huge! The PSP could potentially be disabled! Very little work has gone into handicapping the PSP compared to the IME.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#83https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"
This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.
Seriously. AMD stock is trading up 3+% at the time of my comment, and it's climbed since the disclosures this morning.
Something tells me this backfired.
Discl: I've been long AMD for a long frickin' time.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#84>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…
Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…
I’ll add 3. It’s not all about the researchers and AMD, but the people who use AMD chips and deserve a modicum of protection and consideration. Unless there were exploits in the wild, the security of users seems not to have entered into this.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#85>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…
Yeah it's suspicious. The website[1] has many fancy infographics, marketable names and fear mongering but you have to dig into the whitepaper[2] to find any details about the actual vulnerabilities. And even then it starts only on page 8 of 20 and you discover that it's vulnerabilities targeting the secure boot infrastructure and you need local admin to exploit them. It's not good but it's not a new Spectre or Meltdo…
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#86Earlier quoted context omitted.
Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…
>Independent researchers don't owe AMD a chance to address anything. The goal of responsible disclosure windows have nothing to do with saving face for the company. The point is that it gives the company time to come out with a fix so that their customers aren't left with massive holes in the security of their systems.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#87Earlier quoted context omitted.
This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.
A new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices…
I strongly doubt that. I've seen incredibly serious vulnerabilities I've reported firsthand have little to no impact on a company's valuation when publicized.
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#88>All of the exploits require elevated administrator access, with MasterKey going as far as a BIOS reflash on top of that. CTS-Labs goes on the offensive however, stating that it ‘raises concerning questions regarding security practices, auditing, and quality controls at AMD’, as well as saying that the ‘vulnerabilities amount to complete disregard of fundamental security principles’. This is very strong wording indee…
Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…
3. The vulnerabilities are real, but their impact is being overstated because behind the security researchers is a financial firm hoping to make a buck on stock trades.
#3 would seem to me to be a bad development for your niche, if it became a popular business model.
(I have no horse in this race.)
Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#89Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice
#90Earlier quoted context omitted.
Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…
People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…
This isn't "shoot the hostages". The researchers didn't manufacture the vulnerabilities; AMD did. If 4 dudes in a basement can find exploitable driver vulnerabilities, so can 10 researchers none of us will never have heard of working in a nondescript office somewhere in Bulgaria. The only moral differences is that these 4 dudes told us about what they found --- something else they had no actual obligation to do.
Again: it seems really likely that these vulnerabilities have been hyped way out of proportion to their real impact. I think it's reasonable to be irritated by that (again, though: this isn't a first). But other than that, I don't understand how people arrive at the conclusion that independent security researchers owe strangers the results of their work.