> AMD is in the process of responding to the claims, but was only given 24 hours of notice rather than the typical 90 days for standard vulnerability disclosure. No official reason was given for the shortened time.
90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional.
And the users downstream of bugs that are made more widely vulnerable--because, as anyone who saw how, as an example, previously rare MitM attacks became commonplace after Firesheep etc. were publicized, obscurity is in fact a component of security--are...?
Well, fuck 'em, I guess.
Responsible disclosure, contrary to the super-cool leet kid notions expressed by people with who choose to exhibit an underdeveloped social conscience, is not doing a solid for the companies who have vulnerabilities. It's for the users who consume things. Security researchers are effectively taking upon themselves a role of public service. That comes with responsibilities to the public, not to AMD or whoever.
Meanwhile, this crew looks like they briefed the media before telling the vendor, which is all kinds of fucked.
Here's the strongest version of the claim that I understand:
1. All of the relevant people, i.e. "the users downstream of bugs" are already vulnerable.
2. It's possible, maybe even probable (or likely), that people, other than the researchers that are disclosing the vulnerability, have also discovered the same vulnerability and, furthermore, that those others can exploit the vulnerability.
3. Every delay in disclosing the vulnerability prevents the victims from protecting themselves from any bad actors mentioned in [2] thru means more drastic than applying a patch or similar from the relevant vendors (e.g. taking the affected components offline or otherwise making them unavailable).
The argument hinges on the probable size of the bad actors mentioned in [2]. If you assume that the disclosing researchers are the first people to discover the vulnerability, then it would possibly be best for them to first disclose the vulnerability to the relevant vendor or vendors. But note that even vulnerabilities disclosed to vendors can be leaked to bad actors.
And if you don't assume that the disclosing researchers are the first people to discover the vulnerability, then not disclosing ASAP prevents people from protecting themselves.
I think your perspective is a bit narrow. If you consider each individual person, [3] is indeed nonsense. However, the impact of many hacks comes disproportionally from high-value targets.
Some high-value targets (e.g. key infrastructure, parts of government, major enterprises) have dedicated security teams, and can come up with a pretty decent response if given the appropriate information. Divulging vulnerability information widely, in particular, may or may not be a net benefit to them. (Consider e.g. Linux vendor vulnerability lists.)
Other high-value targets (e.g. journalists, human-rights activists, etc.) are utterly outgunned by their adversaries (who can afford to buy or find new vulnerabilities), and can only hope that something causes vendors to consistently write software that's sufficiently-uneconomic to exploit. In the sufficiently-long run, proponents of full disclosure would argue, anything that increases the cost of shipping vulnerable software should help these users.
(Disclaimer: absolutely not speaking for my employer here.)
Nobody appointed these security researchers to the authority to which you assign to their actions, though. Burning the immediate user on the off chance that it helps the hypothetical future user is some very weak tea.
I agree that some proponents of immediate disclosure would claim that their actions encourage vendors to ship less vulnerable hardware or software. I do not believe that that, in the general case, is why it is being done. And I am certain that that, in this specific case, is not why it was done.
Well, the very idea that there is some timelimit on mitigation before the flaw is disclosed anyways is that "very weak tea".
However, overall, I agree with you. Person with exploit needs to compare the probable consequences of disclosing at time N vs. disclosing at time N+1.
If it's being exploited in the wild and users can meaningfully self-protect, disclose now!
If the vendor will probably have a patch in 2 weeks, there is not widespread exploitation of the vulnerability, and disclosing now will cause widespread exploitation, disclose in 2 weeks.
If the vendor seems like they will never issue a patch on their own (because significant time has elapsed), such that at some point in the future there's going to be widespread exploitation and you're only hastening that a bit, go ahead and disclose now.
It is neither the vendor nor the researcher’s place to make those sorts of decisions on behalf of the end user, while keeping the end user ignorant of the fact that such a decision has been made for them.
Or selectively telling your buddies in teh know and helping them to fix their shit, while keeping uncool kids out of the loop. Now that's irresponsible.
Politeness is optional too, but people still prefer to not be needlessly rude. It is quite normal to balance doing your job with trying to reducing harm to users who had nothing to do with this.
A few (far from all!) software vendors realistically might be able to respond and issue a patch in 24 hours. But a hardware vendor cannot. See Intel's recent debacle [1] for what happens when a silicon vendor rushes a security fix out of the door without going through a proper multi-week QA cycle.
And at other times 90 days maybe inadequately short. But 90 is just a round number someone at Google thought is a good idea. And now it's become 'standard'.
I can go with immediate, or I can go with never. But realize that every vuln is different, and their impact (or hardship of writing or applying patches) may not always be fully understood by stakeholders involved before or immediately after the details are released [CVE-2015-0235].
No it isn't, not even slightly. This is completely irresponsible. They are publishing a zero day vulnerability. Completely unprofessional and reckless.
Fortunately for us all the actual exposure is minimal.
90 days is not a standard. Nothing was shortened. People are allowed to publish their research whenever they like. Vendor advance notification is optional.
Full, immediate disclosure is responsible.