13 ms·
Amazing coincidence! On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With il
by goodmachine 9y ago
Amazing coincidence!
On the very same day this information came out, 'Viceroy Research Group' managed to release a 33-page 'analysis' of these results. With illustrations.
Headline:
>We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11 (Bankruptcy) in order to effectively deal with the repercussions of recent discoveries.
Viceroy Research lists no employees or contact address, but it appears they are not a crack team of hardworking & incisive business analysts, but two Australian teenagers and a former UK child social worker, struck off in 2014 for misconduct.
They have previous form in producing or plugging short-call stories (quite effectively), and latterly investigated by South African media for similar shady business.
https://www.moneyweb.co.za/in-depth/investigations/viceroy-unmasked/ https://www.moneyweb.co.za/in-depth/investigations/viceroy-u...
It took very little internet sleuthing to find this stuff out. None of the tech press bothered to do so.
Disclaimer: I have no position in AMD.
Edit: link to Viceroy https://viceroyresearch.org/ https://viceroyresearch.org/
- yuhong 9y agoI even thought Meltdown/Spectre was overblown, and the average user will never see these attacks.
- tptacek 9y agoThen you were wrong, since those attacks against unpatched, unhardened hosts are trivially weaponizable through browser Javascript.
- Lerc 9y agoCan you point to a javascript example? I can think of a number of approaches, but nothing I could catergorise as trivial.
- grub5000 9y agoFirst hit for googling "Spectre Javascript POC": https://github.com/ascendr/spectre-chrome https://github.com/ascendr/spectre-chrome
- therein 9y ago> Enable `#shared-array-buffer` in `chrome:///flags` under your own risk...
- tptacek 9y agoSharedArrayBuffer was disabled exactly because vulnerabilities like this are easily exploitable (but there are POCs that don't depend on it).
- mtgx 9y agoEvery single browser had to disable that feature because of those flaws.
- ComputerGuru 9y agoIt was only disabled as a mitigation to these specific attacks, in case you though it was an experimental or “at your own risk” type of thing.
- daira 9y agoDisabling SharedArrayBuffer is just stopping the most obvious method of exploitation; it's by no means a fix. Expect a slew of papers over the next few years on other methods of exploitation from JS.
- guelo 9y agoThey're weaponizable when using a small and rapidly shrinking percentage of unpatched browsers running JavaScript delivered by extremely uncommon websites.
- tptacek 9y agoThat's true because the vulnerability itself wasn't overblown, and was immediately patched.
- api 9y agoAttacks only get better.
- Buge 9y ago>JavaScript delivered by extremely uncommon websites All it takes it emailing them a slightly convincing link, and they're running javascript from one of those "extremely uncommon websites". It doesn't matter how common the website it, a single website can compromise millions of users.
- chmod775 9y agoIf you look at the metadata of both the white paper and the analysis, you can see that the creation time of them is only 2 hours, 50 minutes apart. And that's the creation date, not even when they were published. https://pastebin.com/CcDTz0hB https://pastebin.com/CcDTz0hB
- chmod775 9y ago(Replying to myself because I can't edit my post anymore) Edit: And it gets better! If you check the HTTP headers when requesting the whitepaper from their servers, it will tell you that the file was placed there (last-modified) at 13:22 GMT, so just 1 hour before Viceroy Research Group created their analysis - and probably ages before the actual news broke. https://pastebin.com/gXVd9cff https://pastebin.com/gXVd9cff
- hermitdev 9y agoWell, this could be interesting. AMD is a US listed security. If true, these two lads could very look forward to a visit from the US SEC. Seeing as how market manipulation is not a capital-crime, I don't see Australia objecting to an extradition, should charges be warranted.
- travmatt 9y agoWhich exact crime are you alleging, specifically? Plenty of short sellers investigate companies and their products and make investment decisions based on their findings.
- yellow_postit 9y agoThey tend not to weaponize those findings putting innocent people in harms way.
- nradov 9y agoPerhaps so, but that's not a crime. There's nothing illegal about trading on your own private research.
- tyler_larson 9y agoTrading on research, no. But attempting to artificially manipulate the market while doing so is effectively "pump-and-dump" but short instead of long. A lot comes down to timing and exactly what the communication says. Not a sure-thing conviction, but certainly a dangerous business plan.
- comex 9y agoApparently known as "short and distort". See also "When Does Short Selling Become Manipulation?": http://www.klgates.com/files/tempFiles/901e34d6-b3ee-4ac4-bdad-3b6cabd7060b/Alert_SEC_ShortSelling.pdf http://www.klgates.com/files/tempFiles/901e34d6-b3ee-4ac4-bd...
- smoyer 9y agoHmm ... I was more tempted to dig into connections between the Israeli firm and Intel but your analysis is way better!
- dennisgorelik 9y agoWhy is AMD 1.04% up today then (while technology index is -1.16%)? https://finance.google.com/finance?q=amd https://finance.google.com/finance?q=amd AMD $11.64
- loeg 9y agoLook at the interday pricing. There were some small slumps. Clearly most traders did not react too negatively to the story, at least by the end of the day.
- mtgx 9y agoIf they did this just to short AMD and make money, that's indeed quite shady, and they go through all the trouble of hiding their real intentions because they also know it's super-shady. That said, unless the whole "research" is fake, I wonder if we could be seeing more such tactics in the future against tech companies, and whether or not that would give them an immense incentive to care about security - or risk getting ruined in the stock market. Honestly, such a huge incentive may actually be needed to get most companies to get about security. The money equation needs to make sense to them. Right now most think investing the absolute minim amount in security for compliance reasons is already too much money wasted on security. If this were to become common, I think maximizing security would actually start looking quite profitable to them. I mean, this research is already saying there are some backdoors in AMD's chips. I imagine in the future, companies would be way more careful about allowing backdoors in their products, whether intentionally or by mistake, if they knew they risked getting their stock crushed. So yeah I just like to play with this idea a little bit. So far this revelation doesn't seem to have had the "desired" effect by the backers of the research, though, but we'll see. I just want to know whether or not the research is real, so I'll wait for AMD's confirmation. I assume AMD wouldn't try to lie to us about it, because there are now probably at least a dozen security teams trying to pick AMD's chips apart, so the flaws would be found soon enough, if real.