9 ms·
https://amdflaws.com/disclaimer.html https://amdflaws.com/disclaimer.html "you are advised that we may have, either directly or indirectly, an economic interes
by vesrah 9y ago
https://amdflaws.com/disclaimer.html https://amdflaws.com/disclaimer.html
"you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"
- nodesocket 9y agoAlmost always these types of security incidents and breaches NEVER move stock prices negatively because frankly they don't impact business. $AMD is currently trading up 3.5% as of writing this. :-)
- matt4077 9y agoThat’s... sort of ok? It’s not perfect, but it opens up another avenue to finance security audits besides selling exploits to intelligence services, attacking end-users (both worse), and collecting rewards from the companies (better).
- zitterbewegung 9y agoAMD's stock was negative multiple times today ($11.38 on March 13, 2018 10AM,and at 12Noon on NASDAQ). Shorting the stock would be an obvious play. I have heard of people thinking about trading on security flaws in products but never seen it done in real life.
- swyx 9y agoyes and its $11.77 now (up 2%) this is not in the same league but i recall AMD/INTC also traded up on the spectre/meltdown debate. a lot of insecure chips ironically leads to a lot of demand for new secure-er chips.
- this_user 9y agoThere is also some questionable research group involved in all of this: https://viceroyresearch.org/2018/03/13/amd-the-obituary/ https://viceroyresearch.org/2018/03/13/amd-the-obituary/ It's not uncommon for short sellers to take a position first before releasing a report like this to drive the stock lower. Of course, there are legitimate groups that, in the past, have unearthed real issues and corporate misconduct, but there are also questionable groups that will release reports with little to no substance. This case certainly does looks dubious, but I'd like to see an assessment by reputable security expert.
- dsacco 9y agoI've done it once or twice when I reported a vulnerability directly to a company and I knew they'd have to report it to downstream customers pretty quickly. I've also been in discussions for larger vulnerabilities with security-focused hedge funds such as Muddy Waters. Generally I'm weakly skeptical about profiting from it consistently. In particular, funds like Muddy Waters have a pretty high bar for the sort of vulnerability they're willing to work with. You need not only a severe vulnerability, but the right kind of vulnerability, so you know that it can't be swept under the rug. That said, it's pretty striking to me how aggressive this disclosure is. It may be an attempt to narrow the window and increase the profitability of a short sell.
- deleted 9y ago[deleted]
- swyx 9y agoi always find the importance of these disclaimers blown way out of proportion to their probable economic impact. AMD shares are -up- 2% right now, for a presumably negative piece of news. the stock market is a big and sometimes inscrutable place. but ethics likes to treat things as morally black and white.
- samfriedman 9y agoIs this kind of language common in other security disclosures?
- tptacek 9y agoNo, this is a first. Even MedSec was more coy than this.
- stevievee 9y agoThis is too well organized and presented. My guess is that this has to be financed in some part by a group of short-sellers. They made a rookie mistake though - AMD is plagued by day-traders and algorithms who couldn't give a damn about the fundamentals. Boy the future of capital markets is looking grim.
- ldayley 9y agoA new twist on an old game. I hear people ask why short-selling exists, but’s a good check against corruption but prone to it’s own abuses. Citron Research (a short-sell shop) is a good example of this— they savaged companies like NQ Mobile, Lumber Liquidators, etc. and make a bundle doing it. The security angle is a fascinating and concerning new development, however. That said it may encourage more secure practices (as opposed to theater) through the hardware/software lifecycle in response to serious fundamental design problems. It will also serve to increase the premium on 0days...
- dsacco 9y ago> It will also serve to increase the premium on 0days... I strongly doubt that. I've seen incredibly serious vulnerabilities I've reported firsthand have little to no impact on a company's valuation when publicized.
- kingbirdy 9y agoBut did you create an entire website about the vulnerability, including graphics and headline-friendly names, as well as sending out briefings to major media outlets ahead of the disclosure? Because that's what this group did
- dsacco 9y agoAdmittedly no, but considering AMD is up ~3.85% as of this writing, I'm not sure I'd have benefitted from doing so.
- askafriend 9y ago
- mcintyre1994 9y agoMentioned in another comment, but from their management page: http://www.cts-labs.com/management-team http://www.cts-labs.com/management-team > He [Yaron, CFO] is also the founder and Managing Director of NineWells Capital, a hedge fund that invests in public equities internationally. I wonder how linked the companies are - is this basically a vulnerability research company as a research arm of a hedge fund?
- tptacek 9y agoIt sure seems that way. It wouldn't be the first; look, for instance, at Justine Bone's MedSec.
- microtherion 9y agoThere was also Mark Cuban's Sharesleuth: https://www.wired.com/2007/09/mf-sharesleuth/ https://www.wired.com/2007/09/mf-sharesleuth/
- deleted 9y ago[deleted]
- tgsovlerkhgsel 9y agoDoesn't seem to have a noticeable impact though, and based on the (lack of) impact of most previous security issues, I wouldn't have expected it either.
- GordonS 9y ago... And yet they give 24h notice. Yeah, right, this is definitely not being used to affect the share price!
- hdyr 9y agoThese guys are essentially more black hat than white hat
- dsacco 9y agoNo they aren't. Aside from the inherent and obvious lack of nuance in that terminology, black hats do not report their vulnerabilities. They weaponize them and use them, or they sell them to criminal organizations.
- Sir_Cmpwn 9y agoBlack hat isn't distinguished by failing to report vunlerabilities. It's distinguished by bad faith.
- dsacco 9y agoNo, it's actually not. It's distinguished precisely by using a vulnerability with the intention to compromise others. You can't just redefine "black hat" to be whatever normative disagreement you have with how people choose to disclose vulnerabilities. That's entirely subjective.
- robrenaud 9y agoThis is what wikipedia says: A black hat hacker (or black-hat hacker) is a hacker who "violates computer security for little reason beyond maliciousness or for personal gain" The personal gain part certainly fits with short selling the stock.
- dsacco 9y agoExcellent, great citation! Now, precisely what did the security researchers hack for their own gain, and precisely which computer's security was violated? If we can call them "hackers" just because they ostensibly compromised their own hardware or software as a proof of concept for the vulnerability research, does that mean that all of Google's Project Zero consists of hackers and black hats because they get paid (personal gain) by Google to find security vulnerabilities?
- volgo 9y agoPeople here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on. This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company For example, a short seller last year revealed (through extensive research), that Valeant Pharmaceuticals was stuffing its channels and faking its finances. He placed a huge sort sell and went public with the damaging info - tanking the stock from $270 to $12 and made a ton of profit off of it: https://www.nytimes.com/2017/06/08/magazine/the-bounty-hunter-of-wall-street.html https://www.nytimes.com/2017/06/08/magazine/the-bounty-hunte... Without this incentive, why would anyone bother to reveal damaging info? You're placing your self as a target with no reward. The payment is the natural balance of the market. So yes, this research firm is connected w a hedge fund, and they have a very vested interest. But that doesn't make their claim untrue
- rebuilder 9y agoHaving a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.
- zrm 9y ago> Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though. A good way for companies to prevent this is to have a generous bug bounty program. Money is still transferred from the shareholders to the researchers, but then the company can impose conditions like delaying public disclosure for a reasonable time to prepare a fix.
- deong 9y agoIf it's actually someone attempting to make money on a short or to benefit from a working relationship with a competitor, then a bug bounty program does nothing. No one can run a bounty program that pays out anywhere near as much as the information is actually worth to an adversary. Bug bounties work to engender a bit of good will among researchers and to provide some incentive to an otherwise neutral party to play ball. They don't mean shit to a hedge fund or a competitor in a multi-billion dollar industry.
- Sir_Cmpwn 9y agoFrom "Viceroy Research": >We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries. Direct quote from: https://viceroyresearch.files.wordpress.com/2018/03/amd-the-obituary-13-mar-2018.pdf https://viceroyresearch.files.wordpress.com/2018/03/amd-the-... These guys are slimy as hell, this is disgusting.
- kbenson 9y agoAt what point does it go from being legal (utilizing information that anyone could have discovered with enough time and effort, whether through short sale or investment) to illegal (stock manipulation through rumor or innuendo)? This qualifies in my eyes, but it's probably hard to prove when one is attached to the other. I agree, it does feel slimy.