Live data from Hacker News

The RCE that AMD won't fix

mrbruh.com

81–90 of 182 posts

Re: The RCE that AMD won't fix

#81
post #22

One good thing we can say about Linux bundling all the drivers is that it obviates the need to run almost all of this type of low quality (if not outright spyware) driver management software. They are especially problematic because they can't be sandboxed easily like most other proprietary crap. For whatever reason, distro maintainers working for free seem a lot more competent with security than billion dollar hardwa…

You don't really need to run these updaters on windows.

Re: The RCE that AMD won't fix

#82
post #24
post #11

It's not directly an RCE unto itself, it requires something else. A compromised DNS on the network, e.g. So no surprise they ignored it. Also, if AMD is getting overwhelmed with security reports (a la curl), it's also not surprising. Particularly if people are using AI to turn bug bounties into income. Lastly if it requires a compromised DNS server, someone would probably point out a much easier way to compromise the…

As someone that works security, the whole "A compromised DNS on the network" would be a total excuse not to pay. The fact is allowing any type of unsigned update on HTTP is a security flaw in itself. >someone would probably point out a much easier way to compromise the networ No, not really. That's why every other application on the planet that does security of any kind uses either signed binaries or they use HTTPSON…

> The fact is allowing any type of unsigned update on HTTP is a security flaw in itself.

Reminds me about ten years or so ago when I was installing Debian or something and I noticed the URL for the apt install mirrors were http and not https. People helpfully pointed out this is a non issue because the updates are signed.

Ok I guess but then why did Debian switch to https?

Re: The RCE that AMD won't fix

#83
Auto Update is EVERYTIME a RCE. When the software checks a signature, you just need the key. And the delivering enterprise have the key. EVERYTIME.

Don't understand why most people mean auto updating software would in any way create more security. It just creates more attack vectors for every software that has a auto updater.

Re: The RCE that AMD won't fix

#84

Earlier quoted context omitted.

This is oh sweet summer child stuff. Have you ever gone to a crowded public place and setup an open hotspot?

Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.

And you have them in your laptop? Or just using your phone and don't own a laptop at all?

Re: The RCE that AMD won't fix

#85

Earlier quoted context omitted.

This is oh sweet summer child stuff. Have you ever gone to a crowded public place and setup an open hotspot?

Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.

Never travelled to another country and needed internet before you could get a local sim working?

Re: The RCE that AMD won't fix

#87
post #39

AMD AutoUpdate terminal always pops up at midnight for me and then requires me to dismiss it. I've been meaning to uninstall this but always forget about it the next morning. Now I have good reason to block it entirely and go back to manual updates

When I still used Windows that console window would show up and hang for hours. I'd finally close it when shutting down my PC, and it was guaranteed that the driver would be gone on the next boot and I'd need to install it again.

It's the shittest autoupdater I had to ever deal with. It never actually managed to install an update.

Re: The RCE that AMD won't fix

#88

Earlier quoted context omitted.

Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.

And you have them in your laptop? Or just using your phone and don't own a laptop at all?

I would use my phone's 'hotspot' long before I tried random wifi on my laptop?

Re: The RCE that AMD won't fix

#89

Earlier quoted context omitted.

Ah I think I never had to do connect to a public open hotspot because by the time I grew up 4G and then 5G internet were commonplace.

Never travelled to another country and needed internet before you could get a local sim working?

esim for the win.

Re: The RCE that AMD won't fix

#90
Can anyone rationalize this decision? Sure technically this is outside the stated scope however the severity of this vulnerability is immediately obvious, which should trigger some alarm bells that the scope needs to be reconsidered.

If they lose just one customer over this they're losing more than the minimum $500 bounty. They also signal to the world that they care more about some scope document than actually improving security, discouraging future hackers from engaging with their program.

This would be a high severity vulnerability so even paying out $500 for a low severity would be a bit of a disgrace.

What's the business case for screwing someone out of a bounty on a technicality?

Post reply on HN