Live data from Hacker News

Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

anandtech.com

91–100 of 359 posts

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#91
post #77
post #38

Earlier quoted context omitted.

Independent researchers don't owe AMD a chance to address anything. They bought the chips on the open market where AMD makes them available, and then used their own time and materials to conduct their own research. Their work product is their own, and AMD has no claim to it. There are, as I see it, two rational, coherent ways to be outraged about this story: 1. The vulnerabilities are fabricated and the report is fra…

What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview. https://www.iso.org/standard/45170.html

Responsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans.

https://hn.algolia.com/?query=author:tptacek%20responsible%2...

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#92
post #87
post #78

Earlier quoted context omitted.

A new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices…

> It will also serve to increase the premium on 0days... I strongly doubt that. I've seen incredibly serious vulnerabilities I've reported firsthand have little to no impact on a company's valuation when publicized.

But did you create an entire website about the vulnerability, including graphics and headline-friendly names, as well as sending out briefings to major media outlets ahead of the disclosure? Because that's what this group did

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#93
post #90
post #76

Earlier quoted context omitted.

People use AMD chips. It's about more than AMD's stock price. I do not need to be a security researcher to understand that they, as with everyone else, have an obligation to the body politic to not be a dick (as in all things!). There are actors who may be aware of this attack already--but, as I mentioned elsethread, wider knowledge of attacks like this have a much higher chance of splashing back on end users who lit…

You can consult the search bar at the bottom of the page to learn that I am 100% OK with immediate, uncoordinated disclosure. It's not what I personally do, but that's easy for me to say because I don't find these kinds of vulnerabilities. This isn't "shoot the hostages". The researchers didn't manufacture the vulnerabilities; AMD did. If 4 dudes in a basement can find exploitable driver vulnerabilities, so can 10 re…

I understand what you are OK with. I am saying that I believe, from a fairly long scope of interaction, you are a better person than that.

They've disseminated widely an attack strategy to people who didn't have it. Nobody except AMD can fix the problem, regardless of the good intentions of other actors--on the other hand, many bad actors can use that information. That's as shoot-the-hostages as it gets.

Security researchers owe "strangers" (which is a really weird term for "society at large" that I don't think you, specifically, would be using with such connotations outside of a security context where you'd already made a decision) the same courtesy they owe everyone else: to not endanger people unnecessarily. I agree with you that this is a relatively minor vulnerability, I'm not hyping it or anything--but it's still a vulnerability, it is still more widely known now, and there is a bigger pool of bad actors than there was last week able to use it against people, irrespective of AMD's stock price.

There's certainly a gray area, if a vendor hasn't acted to fix something you know they know about. I'm not talking about that. But 24 hours and briefing the media before letting AMD know, as it very much seems like they did, is well outside of what I could consider any reasonable gray area.

If you care about end users, and you should because they are your fellow people, you don't publicize how bad actors can hurt them. You just don't. It's just...minimal decency, to care about other people. I can't see it any other way.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#94
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

... And yet they give 24h notice.

Yeah, right, this is definitely not being used to affect the share price!

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#95
post #87

Earlier quoted context omitted.

> It will also serve to increase the premium on 0days... I strongly doubt that. I've seen incredibly serious vulnerabilities I've reported firsthand have little to no impact on a company's valuation when publicized.

But did you create an entire website about the vulnerability, including graphics and headline-friendly names, as well as sending out briefings to major media outlets ahead of the disclosure? Because that's what this group did

Admittedly no, but considering AMD is up ~3.85% as of this writing, I'm not sure I'd have benefitted from doing so.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#96

I think the economics/ethics of the researchers are overshadowing something big: "RYZENFALL allows malicious code to take complete control over the AMD Secure Processor." "Multiple vulnerabilities in AMD Secure Processor firmware allow attackers to infiltrate the Secure Processor." If this is legitimate, this is huge! The PSP could potentially be disabled! Very little work has gone into handicapping the PSP compared…

Well there was a big community push a while ago to have the new AMD cpus have an option to disable the PSP.

I'm gonna wishfully think this was intentionally done to allow us to disable the PSP.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#97
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

This is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.

I agree on the premise of moving the market but they don't necessarily need to be only short sellers, they could have hedged both ways and still made money.

They could have exercised puts if it went down (which it did in the morning) or bought stock/calls both before the site release and in the case of it going down because they knew it wouldn't be a concern or dispelled by AMD.

Unless, this is truly a flaw and in that case, they can still buy more puts and just wait for AMDs official response.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#98
post #28

https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"

These guys are essentially more black hat than white hat

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#99

24hrs notice is unheard of. Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.

They seem to have 3 employees on LinkedIn. The co-founders, at least, seem to have listed experience in security & security consulting.

And (financial) securit_ies_.

Follow the money.

Re: Security Researchers Publish Ryzen Flaws, Gave AMD 24 Hours Prior Notice

#100
post #81
post #33

Earlier quoted context omitted.

Basically a follow the money situation. Could something like this be considered inside information? Or is it legal to actively manipulate stock prices to ones benefit in this way?

To add to the other comments here, a recent high profile case of something similar was Bill Ackman shorting Herbalife. Basically, he shorted the stock and then went to the media with his research showing that he believed Herbalife to be a pyramid scheme. Ultimately, I believe he lost money on the whole fiasco, but it's not an uncommon strategy. The whole thing made the news after a particularly amusing exchange betwe…

I see.. So it could be a viable business to do research like this, short stock and then release the information. It just has to be a bit more damning than this as the stock price is actually up today!

Seems a bit shady in any case if one were to do this in the same way as when companies pay researchers to make claims publicly that benefit the company like the process leading up to the banning of led in petrol etc.

Post reply on HN