Live data from Hacker News

The RCE that AMD wouldn't fix

mrbruh.com

1–10 of 131 posts

Re: The RCE that AMD wouldn't fix

#3
AMD didn't deny it was a vulnerability; they denied it was in the scope of the bounty program.

Remember that at giant tech companies, the incentive is to pay out bounties --- there are people on the vendor's team whose performance is measured in part by how much the program pays out.

Re: The RCE that AMD wouldn't fix

#4
post #3

AMD didn't deny it was a vulnerability; they denied it was in the scope of the bounty program. Remember that at giant tech companies, the incentive is to pay out bounties --- there are people on the vendor's team whose performance is measured in part by how much the program pays out.

What hair is this splitting? The issue was that AMD allowed a known and serious security vulnerability to exist within their customers’ systems, for months, and acted with a lack of candor while doing so.

Re: The RCE that AMD wouldn't fix

#5
post #4
post #3

AMD didn't deny it was a vulnerability; they denied it was in the scope of the bounty program. Remember that at giant tech companies, the incentive is to pay out bounties --- there are people on the vendor's team whose performance is measured in part by how much the program pays out.

What hair is this splitting? The issue was that AMD allowed a known and serious security vulnerability to exist within their customers’ systems, for months, and acted with a lack of candor while doing so.

It's not hair-splitting; it's central to the idea of a bug bounty. Too many people have weird ideas about what bug bounties are for.

Re: The RCE that AMD wouldn't fix

#6
Such a bug could have been exploited by certain big state actors.

Those that have access to international network links.

Those that have the ability to generate new firmware that simply passes the CRC32 checksum.

Re: The RCE that AMD wouldn't fix

#7
post #2

The discussion the video references [1] [1] - https://news.ycombinator.com/item?id=46906947

The original post [1] now includes an update:

  UPDATE! Within a day of this blowing up on Hacker News, AMD reached back 
  out to me and said they would be looking into the matter after all.
[1] https://mrbruh.com/amd2/

Re: The RCE that AMD wouldn't fix

#8
post #5
post #4

Earlier quoted context omitted.

What hair is this splitting? The issue was that AMD allowed a known and serious security vulnerability to exist within their customers’ systems, for months, and acted with a lack of candor while doing so.

It's not hair-splitting; it's central to the idea of a bug bounty. Too many people have weird ideas about what bug bounties are for.

Yeah, like the weird idea that those programs are intended to in some way reduce the number of exploitable bugs actually out there.

Re: The RCE that AMD wouldn't fix

#9
post #3

AMD didn't deny it was a vulnerability; they denied it was in the scope of the bounty program. Remember that at giant tech companies, the incentive is to pay out bounties --- there are people on the vendor's team whose performance is measured in part by how much the program pays out.

They wanted to keep it quiet. As if they did not mind if it was exploited by those with access to international network links.

Re: The RCE that AMD wouldn't fix

#10
post #8
post #5

Earlier quoted context omitted.

It's not hair-splitting; it's central to the idea of a bug bounty. Too many people have weird ideas about what bug bounties are for.

Yeah, like the weird idea that those programs are intended to in some way reduce the number of exploitable bugs actually out there.

That's in fact often not their core purpose!
Post reply on HN