One good thing we can say about Linux bundling all the drivers is that it obviates the need to run almost all of this type of low quality (if not outright spyware) driver management software. They are especially problematic because they can't be sandboxed easily like most other proprietary crap. For whatever reason, distro maintainers working for free seem a lot more competent with security than billion dollar hardwa…
The RCE that AMD won't fix
81–90 of 182 posts
Re: The RCE that AMD won't fix
#82It's not directly an RCE unto itself, it requires something else. A compromised DNS on the network, e.g. So no surprise they ignored it. Also, if AMD is getting overwhelmed with security reports (a la curl), it's also not surprising. Particularly if people are using AI to turn bug bounties into income. Lastly if it requires a compromised DNS server, someone would probably point out a much easier way to compromise the…
As someone that works security, the whole "A compromised DNS on the network" would be a total excuse not to pay. The fact is allowing any type of unsigned update on HTTP is a security flaw in itself. >someone would probably point out a much easier way to compromise the networ No, not really. That's why every other application on the planet that does security of any kind uses either signed binaries or they use HTTPSON…
Reminds me about ten years or so ago when I was installing Debian or something and I noticed the URL for the apt install mirrors were http and not https. People helpfully pointed out this is a non issue because the updates are signed.
Ok I guess but then why did Debian switch to https?
Re: The RCE that AMD won't fix
#83Don't understand why most people mean auto updating software would in any way create more security. It just creates more attack vectors for every software that has a auto updater.
Re: The RCE that AMD won't fix
#84Earlier quoted context omitted.
This is oh sweet summer child stuff. Have you ever gone to a crowded public place and setup an open hotspot?
Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.
Re: The RCE that AMD won't fix
#85Earlier quoted context omitted.
This is oh sweet summer child stuff. Have you ever gone to a crowded public place and setup an open hotspot?
Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.
Re: The RCE that AMD won't fix
#86Spooky, this is not exposure if using Linux?
Re: The RCE that AMD won't fix
#87AMD AutoUpdate terminal always pops up at midnight for me and then requires me to dismiss it. I've been meaning to uninstall this but always forget about it the next morning. Now I have good reason to block it entirely and go back to manual updates
It's the shittest autoupdater I had to ever deal with. It never actually managed to install an update.
Re: The RCE that AMD won't fix
#88Earlier quoted context omitted.
Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.
And you have them in your laptop? Or just using your phone and don't own a laptop at all?
Re: The RCE that AMD won't fix
#89Re: The RCE that AMD won't fix
#90If they lose just one customer over this they're losing more than the minimum $500 bounty. They also signal to the world that they care more about some scope document than actually improving security, discouraging future hackers from engaging with their program.
This would be a high severity vulnerability so even paying out $500 for a low severity would be a bit of a disgrace.
What's the business case for screwing someone out of a bounty on a technicality?