7 ms·
The RCE that AMD wouldn't fix
See also https://www.youtube.com/watch?v=4HjWHNLRMB0 https://www.youtube.com/watch?v=4HjWHNLRMB0
Related: The RCE that AMD won't fix - https://news.ycombinator.com/item?id=46906947 https://news.ycombinator.com/item?id=46906947 - Feb 2026 (173 comments)
- thesuitonym 4mo agoGaslighting does not mean lying.
- happytoexplain 4mo agoYeah, it's annoying. But it's been captured by popular culture as meaning a blatant lie - one where the liar knows the truth is or was available/obvious. A "don't piss on my leg and tell me it's raining" lie. Or, alternatively, and especially in gender relations, any lie intended to manipulate or demean another person. As opposed to lying to protect yourself, to swindle somebody, or some other reason. This is closer to the original idea, but still not there.
- Bender 4mo agoThe discussion the video references [1] [1] - https://news.ycombinator.com/item?id=46906947 https://news.ycombinator.com/item?id=46906947
- scw 4mo agoThe original post [1] now includes an update: UPDATE! Within a day of this blowing up on Hacker News, AMD reached back out to me and said they would be looking into the matter after all. [1] https://mrbruh.com/amd2/ https://mrbruh.com/amd2/
- tptacek 4mo agoAMD didn't deny it was a vulnerability; they denied it was in the scope of the bounty program. Remember that at giant tech companies, the incentive is to pay out bounties --- there are people on the vendor's team whose performance is measured in part by how much the program pays out.
- odyssey7 4mo agoWhat hair is this splitting? The issue was that AMD allowed a known and serious security vulnerability to exist within their customers’ systems, for months, and acted with a lack of candor while doing so.
- tptacek 4mo agoIt's not hair-splitting; it's central to the idea of a bug bounty. Too many people have weird ideas about what bug bounties are for.
- Hizonner 4mo agoYeah, like the weird idea that those programs are intended to in some way reduce the number of exploitable bugs actually out there.
- tptacek 4mo agoThat's in fact often not their core purpose!
- JumpCrisscross 4mo agoWhat is it?
- tptacek 4mo ago(First, I'm sorry I was so terse upthread; I had to get up early for a meeting and was scrolling HN in bed while it was happening without my reading glasses on; I should learn to stop commenting when I'm like that.) I've written about this before here, but to sum it up: * Unless something wild happens in software engineering (formal methods, &c) as a result of AI, there's no such thing as eradicating security vulnerabilities. Focused programs can eliminate low-hanging fruit, but at the point where you're offering significant bounties part of the premise is that all that fruit has been plucked. The marginal security impact of a single bounty award, by itself, is immaterial. * What bounty programs can do is focus internal engineering attention. Large product teams have huge backlogs of issues and security design punch lists. For features and feature bugs, there's a closed loop that prioritizes the work: the market. For security vulnerabilities, bounties serve a similar purpose. This is why many bounties are tightly scoped; the whole point of the program is to direct the efforts of specific product teams. * When we're talking about 10,000+ person engineering teams, the most important thing to know about bug bounty programs is that the company is incentivized to pay out. No major tech company that runs a bounty is "covering up" vulnerabilities. There's no reason for them to do so. They're running a program that ostentatiously pays rewards to people who report vulnerabilities! There are people on the teams managing the bounties who in effect get paid more when the program pays out more: that's what success looks like. You add all this stuff up and all the drama about AMD (or Google or whoever) being shady or stingy basically never add up.
- sakkura 4mo agoSuch a bug could have been exploited by certain big state actors. Those that have access to international network links. Those that have the ability to generate new firmware that simply passes the CRC32 checksum.
- tptacek 4mo agoA bug in a nonfunctional autoupdater. Big state actors. Got it.
- bri3d 4mo agoActual write-up rather than overwrought YouTube drama: https://mrbruh.com/amd2/ https://mrbruh.com/amd2/ A non-default-installation set of AMD tools (Ryzen Master and probably others) had an auto-updater which used HTTP instead of HTTPS. It's clear this is a feature they'd basically forgotten about; it even pointed to an ATI domain. A third-party bug bounty company rejected it because MITM was out of scope. AMD are incompetent at making software (news at 11), kept asking for extensions, and took an incredible amount of time to deal with it. Eventually they removed this updater entirely and replaced it with one in the app (rather than the installer) that uses HTTPS + a CRC32 (for some reason). The initial vuln was very stupid and should have been fixed faster. As for the current system, if you're mad about HTTPS-protected auto-updaters (which is valid), you've probably got a lot of them to go to war against.
- tlb 4mo agoIt's ridiculous to consider MITM attacks out of scope for taking over your computer. Also, there are probably ways to exploit this without a true MITM like DNS cache poisoning. But it's best to just assume the whole internet is MITMed.
- sigmoid10 4mo agoOut of scope does not necessarily mean out of impact. It is merely a question of how far a company wants to be responsible for the environment their software is run in. Most of the time that answer is "not much."
- dlcarrier 4mo agoBut I use a Wi-Fi password, so my phone says it's secure!
- amiga386 4mo agoMITM where attacker needs to install their own CA certs on the victim's device -- sure, out of scope. MITM because you used http instead of https and you don't have any other verified cryptographic signature on your data -- get tae fuck, fix it pronto.
- pietervdvn 4mo agoI'd even count this as "having local access to the device", as that is what is needed to install such a cert
- arcfour 4mo agoI think it's fair to say that requiring local administrative access to the device is out of scope, since you have already completely pwned the device in that case, which is what what you need to install a CA cert on any OSes.
- inlined 4mo agoIn honor of The Old New Thing I call these “Vogon vulnerabilities”: I have a marvelous exploit in mind that pwns anyone I have root access to
- dcminter 4mo agoThe "signature verification" in the fix being CRC32 is pretty hilariously clueless.
- sitkack 4mo agoThey should have done base64 encryption before the crc32. noobs
- throwway120385 4mo agoEspecially because if they had read about or studied this problem they would find tons of prior art where CRC32 was considered not secure for solving the problem. CRC32 solves a different problem -- how do you verify that the data that was received is identical to the data that was sent. It makes no guarantees about who is sending the data, which is the real problem signatures solve.
- wat10000 4mo agoMore specifically, it solves the problem of verifying that the data received was not accidentally corrupted somehow. Unlike cryptographic hashes, CRC32 does not do much to defend against deliberate, malicious modification. It's too easy to craft some different data that matches a given CRC32 value.
- AlotOfReading 4mo agoComputing a CRC is equivalent to attacking it. The checksum is the value that produces a certain fixed constant when appended to the data. This is why you'll often see checksums as the last field in a message. It allows for hardware to verify the entire message by checking if the CRC of the bytes equals that fixed constant without having to parse it.
- deleted 4mo ago[deleted]
- brokenmachine 4mo ago
- bwfan123 4mo ago> In my frustration, I decided to punish this software Love this. I am frustrated by idiot software features everywhere, but am not triggered yet to punish them. AI automation is coming close however.
- hilariously 4mo agoI got so mad at plex/jellyfin's crap I vibe coded an entire entertainment system out of spite. Works great!
- rirze 4mo agoSeems like white hat work is pretty fruitless nowadays. Disappointing.
- inigyou 4mo agoThey keep choosing to work whitehat instead of blackhat, which is all AMD ever wanted.
- qrobit 4mo agopreviously https://news.ycombinator.com/item?id=46906947 https://news.ycombinator.com/item?id=46906947
- mrguyorama 4mo agoAMD software is often utter trash. I am a diehard fanboy of their GPUs, and have been since they were still ATI but I had to finally purchase an nvidia GPU because of how bad AMDs software quality is. My powerful 5700XT spent two years basically broken, because the default, driver provided fan curve locked the fan at 27%. For two years, I couldn't figure out why my GPU constantly crashed, because it was overheating, because the default fan curve prevented the GPU from keeping itself cool and it would eventually just give up. That diagnoses was complicated by the fact that AMD GPUs just resetting is very common. There's a watchdog timer in Windows that resets parts of the GPU stack because Microsoft is traumatized by 60% of Windows Vista BSODs being caused by bad nvidia drivers. Apparently sometimes if you increase this watchdog timer, the GPU eventually finishes whatever was giving it trouble. But I still love AMD, and the ryzen line is a great value in the mid range. So I bought another AMD CPU and am very happy with it. But it somehow included software and this specific auto updater utility. Which I don't need, since I don't want to update the drivers for a GPU that I shouldn't be using (maybe except some video encoding lift, but my GPU can do that too). But I could not figure out a way to kill or prevent this stupid little autoupdater utility which always steals focus, for no reason at all. It shouldn't even be popping up a CLI! Windows task scheduling is incredible and would do this without a problem, and give you all the infrastructure to notice this was happening!
- LooseMarmoset 4mo agoDrivers got better after ATI merged/got bought by AMD, but ATI has a loooooong legacy of terrible drivers in Windows. The funny thing is, in Linux, the drivers are pretty great as far as I can tell. It's not like there aren't bugs, probably, but mostly everything "just works". You can't depend on FSR in Linux, for example - Doom Eternal just goes blank if you turn it on. I can live without it, though, and everything else seems fine, including performance. Nvidia linux drivers make me quite upset - they're fine once you finally get them working, but you approach Nvidia driver updates with extreme caution in Linux
- somat 4mo agoThere is something wrong with the internal fan curve on my old rx580 as well. I ended up writing a controller to manually set the fan speed via the /sys interface. I still need to figure out why the internal curve is not working, but have not gotten around to it because I like my controller so much. The novel bit is that as I was writing it I had an epiphany "Why a curve? What we really want is to close the loop. Set an ideal temperature and figure out the fan speed to maintain it" So my controller has a cute little PID loop to do just that. realistically it never works as I imagined. At idle the temp is lower then the set point at the slowest fan speed and at load the full speed fan keeps it ~ 10C higher than the set point(perhaps this means my set point should be higher?). but sometimes I get that goldilocks midrange load and it works great.
- nickdothutton 4mo agoAMD's inability to make good software has been a recurring problem for decades. Many years ago I had some success with their optimising compiler, but everything else I've touched was bad. A real pity.
- RachelF 4mo agoYes, their software is terrible across CPUs and GPUs, and continues to be. So many trivial bugs just never fixed. It has literally cost them a Trillion dollars in market cap - Nvidia's CUDA is a big reason they're so much bigger than AMD.
- voakbasda 4mo agoAnd that’s saying something, because the CUDA stack is a PITA.
- Bilal_io 4mo agoTheir pay is shit. I interviewed with them 3 years ago and they offered me peanuts I rejected their offer.
- cute_boi 4mo agoAMD somehow got success, but their company culture and pay is shit. They expect PHD level experience but expect pay like peanuts....
- ethbr1 4mo ago> expect PHD level experience but expect pay like peanuts Thought this was par for the course in closer-to-hardware engineering. Never understood why the objectively way harder jobs pay so much worse as an industry.
- greenavocado 4mo agoAcademic overproduction?
- ezoe 4mo ago> If you are an AMD user... Don't bother to use Windows?
- Dwedit 4mo agoThere's two requests involved for the auto updater, one to grab the XML file, and one to grab the driver file over plain http. If the autoupdater can't handle the redirection when grabbing the XML file, then it's a case of accidental safety by mistake that would prevent grabbing the plain http file.
- OkayPhysicist 4mo agoAMD's utter incompetence when it comes to the software side of things is truly, truly baffling to me. It's not like you need a mountain of developers, a team or two on the right project would do wonders for their market share. For example: Implement the CUDA. CUDA's won, hands down, that toothpaste is solidly outside the tube. Luckily, to the outside observer CUDA is just an API, and API's aren't copyrightable. Literally nothing is stopping AMD from hiring a relatively small team of developers to make AMD GPUs CUDA-compatible.
- z3ratul163071 4mo agolikewise. i'm bewildered throughout the years. my suspicion is that it is the company culture: the hardware engineers are the real engineers. software is a triviality left for the lesser minds. the consequence is they mess up every product... everything they do needs software.
- actionfromafar 4mo agoThe argument I have read here on HN, is that CUDA is made for NVidia hardware, and the AMD hardware is not the best fit. Essentially it forces AMD to play by NVidias rules, exactly like how they were forced to follow Intel rules. (Ignore for a second that the API / ISA boundary is different.) But despite that, I also believe AMD would be better off just implementing CUDA.
- rincebrain 4mo agoThey did, apparently, at one point pay someone to build that glue, and then threw it out and wouldn't let the author release it so he's been reimplementing it out of...spite? Burning desire? Unclear. [1] I can't imagine the logic involved in "this is implemented, let's toss it in the dumpster" for that. [1] - https://vosen.github.io/ZLUDA/blog/zludas-third-life/ https://vosen.github.io/ZLUDA/blog/zludas-third-life/
- hgoel 4mo agoHIP tries to be like this, almost API compatible with CUDA such that you just need to do find and replace. I think they even had a script to do this for you. But the issue remains that the actual support and debugging tools remain so atrocious that it doesn't help to combat the CUDA monopoly. They've further burned a lot of trust by never really delivering on their promises to do better unless you're a customer large enough to get personalized attention from their engineers. This ends up being a double whammy because not only are you pushing away smaller businesses, you're also pushing away single developers that go on to influence purchasing/development decisions.
- leecommamichael 4mo agoThank you for looking into this, I also have the annoying pop-up and have been suspicious of it…
- deleted 4mo ago[deleted]
- deleted 4mo ago[deleted]
- dmitrygr 4mo agoI think we can all agree that MiTM is a valid attack vector and this should have paid out the bounty. AMD won't do it, but perhaps we can crowdsource it - the dude deserves it. Join me in doing this: https://ko-fi.com/mrbruhh https://ko-fi.com/mrbruhh (identical link to the one in the write up, feel free to verify). I started it with $100 - https://ko-fi.com/transactions/03df753c-09b0-4972-8e53-adf060985f17/thank-you https://ko-fi.com/transactions/03df753c-09b0-4972-8e53-adf06...
- greenavocado 4mo agoCongratulations, you found the government backdoor!
- brikym 4mo agoGlowing!
- Terr_ 4mo ago> Final update: A couple of days before the embargo ended (and after I wrote the majority of this blog post), AMD told me what their patch for this vulnerability is [...] Although it is true that they now fully use HTTPS, the claim about signature verification is untrue; they only perform a CRC-32 check on the downloaded executable, which is not cryptographically secure. So solves the MITM, but massive infection is still trivial if someone compromises the webserver.
- notepad0x90 4mo agowhat are the chances of them caring so little, but implementing a dedicated signing server, HSM,etc..? even if they sign it, it will probably be done on the same web server.
- SahAssar 4mo ago> someone compromises the webserver Sure, but that's true for 99% of things. Unless you establish trust outside of the normal distribution channel how would you protect against this? What is your proposed channel that is not bootstrapped from HTTPS PKI?
- rwmj 4mo agoAMD (and Intel and everyone else) processors already have an HSM inside for confidential computing so use that? I would hope the HSM isn't as badly implemented as this update mechanism, but then again ...
- bravetraveler 4mo agoThere was a time when RDRAND on Zen gave all zeroes, or something, so eh... I'm happy enough with TLS introduced: knowing the server I'm reaching for updates is actually 'amd.com'. Signatures would be nice, sure, but I wouldn't consider them nearly as critical or useful until now. Before we get too caught up in signatures, however, I'd like to see their new/improved updater actually take precedence. As things stand, I'm not sure key rotation would go well... the updater doesn't mind itself, apparently.
- deleted 4mo ago[deleted]
- deleted 4mo ago[deleted]
- xyst 4mo agoMulti billion dollar company, by the way.
- LearnYouALisp 4mo agoI say the same when I dealt with Amazon's website, and to a smaller extent eBay.com. Don't forget Facebook Marketplace.
- asveikau 4mo ago> 124 days to get AMD to add an s to a couple of HTTP URLs! I disagree that they should only add HTTPS and call it done. They should also add some kind of signing check before running the payload. If anything I'd say HTTPS is optional if they do that part.
- ForOldHack 4mo agoLet this lesson be learned: "In my frustration, I decided to punish this software by decompiling it to figure out how it worked," Note to self: Never piss off a programmer, while he is gaming. To quote: "You're gonna die for that." -Duke Nukem.
- protocolture 4mo agoAMD, just pay the man. You want this stuff disclosed to you.
- helterskelter 4mo agoJesus after reading this I'm wondering if I want to switch my AMD Framework 13 Pro order to Intel, but the IME runs on Java if memory serves and it's not like they'll be any more secure. I just hope we can get Libreboot working with Framework sometime.
- robotnikman 4mo agoWell that explains why I get that random console pop up from time to time, thanks for the insight into what's going on!
- gettingoverit 4mo agoThe last time I remember, the green company did the same HTTP thing literally with their driver downloads from the website, and refused to fix it. Makes me wonder, how much of that 4 month delay was spent deliberating with the state actor. As if there was Prism, and both companies were legally bound to allow MitM to happen, and thus don't have a bug bounty for it.
- nyanpasu64 4mo agoIt doesn't smell like a state actor to me, just gross negligence. Brushing up on the Reddit comment we wrote, the MITM isn't exploitable by default, since the client will error out at the 301 redirect and leave an obvious black window on the user's desktop. Exploiting a user would require replacing the 301 redirect with a direct download, which requires the same amount of effort whether the default disclosure was broken or not. Now if they could've started shipping a modified AMD auto update that followed redirects, that would allow them to pwn users of the updated program. But it would do nothing to people who had installed older versions, up to the version the author installed (which left a black window open indicating the downloads never completed)...
- RandyOrion 4mo agoHilarious read. I laugh out loud multiple times during the read. In the end, I think amd should pay the author simply for the will of debugging for a broken software written by amd, as well as the sheer amounts of loose ends this exploration leads to.
- tgsovlerkhgsel 4mo agoThis is a pretty common behavior that I've seen from bug bounty programs: > a blog post discussing this issue has already been published, which does not appear to be in accordance with the program’s terms. Companies reject bugs as out of scope and/or sit on them forever, then use the bug bounty ToS as intimidation to keep people from disclosing them. And sadly, it works. I'm adding AMD to my list of companies that prefer their bug reports to be a public full disclosure rather than attempting to go through their bug bounty program.
- stuaxo 4mo agoOof, the list of all the unpaid bounties is bad. I'd make it worse by having the amount next to each and a running total.