3 ms·
What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any sec
by devy 9y ago
What about responsible disclosure ethics? Yeah they don't owe AMD anything but all AMD users lose - since they claimed there is virtually impossible for any security product to mitigate those vulnerabilities in their televised security vulnerability disclosure interview.
https://www.iso.org/standard/45170.html https://www.iso.org/standard/45170.html
- tptacek 9y agoResponsible disclosure is an Orwellian term literally coined by vendors as a way to coerce researchers into adhering to vendor schedules and vendor PR plans. https://hn.algolia.com/?query=author:tptacek%20responsible%20disclosure&sort=byDate&prefix&page=0&dateRange=all&type=comment https://hn.algolia.com/?query=author:tptacek%20responsible%2...
- devy 9y agoSo you believer in the absolute freedom of security vulnerabilities disclosures and security researchers should just do so at will? Do you know that the general public are usually the ultimate victims and impacted by those vulnerabilities the most? Especially Intel/AMD are corporations worth tens of billions monopolies in their fields, and if their CPUs with zero days unpatched and sample code and exploitation techniques out in the wild, what else are you gonna use on your desktop computers? We've seen similar happened for Microsoft after Shadow Brokers's disclosure.[1] It's gonna be worse for hardware products as it's virtually impossible to retroactively fix silicons chips. [1]: https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-hacked-world/ https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-...
- tptacek 9y agoWhat happened after the Shadow Brokers? Are we using dogs now to detect the Terminators?
- devy 9y agoBtw, your HN search result page links to all of the references that you THINK what the term "Responsible disclosure" means. Be it "coordinated disclosure" or whatever else, I don't care. But I don't think it's ethical to disclosure the security vulnerabilities to the wild without contacting the vendor and given them a timeline (should be MUCH LONGER than 24 hours) and the benefit of doubt first. Hypothetically speaking, if you are researching vulnerabilities solely for the intent of money (because you can sell to them to 3rd parties or your side hedge fund business can profit from disclosures in the stock market) then shame on you, because you are doing the society a dis-service and gaining on everyone' losses. To me, you are as evil as those hacker who utilize them.
- rphlx 9y agoThere's a decent counterargument - take it or leave it - that this kind of research is extremely difficult and expensive, and upon success, privately weaponizing it and/or selling it to organized crime or nation state-level actors is extremely attractive, and therefore, the ability to short the stock of a sloppy/insufficiently-careful HW vendor to fully or partially fund the research instead is legitimate in that it ultimately improves overall-societal welfare relative to those other alternatives. Vendors who wish to discourage that behavior could offer comparably-large bug bounties instead. And, of course, make their products more secure in the first place.
- paulmd 9y agoSeriously, if some fly-by-night security outfit has managed to discover this, they're probably not the only ones. They didn't blow full technical details on this exploit after 24 hours, they went public with a summary... one that's so high-level that many people are even doubting they exist. That's not exactly dumping a zero-day on the internet either. There's a whole lot of shooting-the-messenger going on with this topic. Making plays against the stock is scummy and possibly illegal, but that doesn't make the exploits here any less real (assuming they are). These are actually quite serious breaks, potentially VMs can jump the sandbox straight into SMM mode and PSP, so it actually is much more severe than just "root password lets you do root things". https://twitter.com/c7zero/status/973668616183754753 https://twitter.com/c7zero/status/973668616183754753 There is a long and storied history of showing the disadvantages of your competitor's products. Edison went on a campaign against Westinghouse's AC electricity, culminating in him electrocuting an elephant to death to demonstrate how dangerous it is. Right now we need more spotlights on computer security than ever, and as long as it gets bugs patched (hardware, software, or firmware) I don't really care who's doing it or what their short-run motivations are. If AMD won't secure their code appropriately and Intel wants to call them out, fine. If Intel is leaking timings through sidechannels and AMD wants to call them out on it, fine. And if we want to throw stones here, it was AMD who blew the embargo on Meltdown a week early because they wanted to force a response from Intel at CES... different in degree, not really in kind.
- paulmd 9y agoBTW, one of the twitter threads went into their disclosure philosophy. https://twitter.com/gadievron/status/973655683269873664 https://twitter.com/gadievron/status/973655683269873664 It turns out it's exactly the "release a general idea to the public to light a fire under the vendor's ass, only release exact technical details to the people who need to know" that you might expect. They didn't dump a zero-day into public.
- GordonS 9y agoLet's use "coordinated disclosure" then - that is generally considered the preferred method these days.
- Digital-Citizen 9y ago> What about responsible disclosure ethics? "Responsible" to whom? Terms like these indicate what side one takes, such as how one expands the term "DRM": digital rights management means taking the 1%/elite side favored by the publisher, the few in power. 'Digital restrictions management' highlights what's happening from the user's side, the 99%, the side of the many. Similarly with the harm to the users and the desire for freedom in the term "jailbreaking". So, since we recognize the reporters owe AMD nothing, to whom are they "responsible"? Or what are they responsible for? This phrase strikes me as useless except to try to foist a responsibility on people that they don't actually have and getting the relatively powerless to serve the interests of power -- users who can't inspect, edit, or share edited CPU microcode are somehow not acting responsibly if they don't give proprietors sufficient notice. Where is the "responsible disclosure" for Intel when they refuse to let users fully control the signing keys used in the software that sees every network packet before the rest of the computer (for inbound network traffic) and before a packet leaves the computer (for outbound traffic)? The one-sidedness of it all sticks out like a sore thumb.