Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Who do you think you speak for? Assuming the vulnerabilities aren't fabricated --- it's happened before with other companies --- attaching your name to that white paper probably guarantees you lifetime employment in security research.

"Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.



Perhaps this is my ignorance, but I was under the impression that security disclosures are usually tightly coordinated to minimize exposure of innocent users.

> "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

Could you point me to an example of a zero warning disclosure that exposed a large amount of users without first attempting to coordinate with the responsible party?


Some researchers coordinate, some researchers don't. For a project originally organized around the principle of getting not just research results but functioning exploit code deployed regardless of vendor preparedness, look no further than Metasploit.


Wait, Metasploit of all things? They have been doing coordinated disclosure since forever.


> "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.

Individuals sometimes do this, security companies very rarely - and both are shunned by the infosec community at large when they do so, as this is very unethical behaviour.

They registered the domain a couple of weeks ago - why give AMD only 24 hours notice?

In this case it does seem highly likely there is some stock market skullduggery afoot.


No, they are not "shunned by the infosec community", no matter how nice that narrative sounds to you.


No need for the attitude.

Just take a look on twitter at what prominent members of the community are saying - they are not impressed with this behaviour. I'm also a member of that community, and hold the same view.

The vast majority of the infosec community promote coordinated disclosure.


If you're referring to vulnerability research twitter, and not, I don't know, IT security twitter, then no that's not what's happening.

The CTS-Labs people are taking shit from vulnerability research twitter for overhyping the findings (meaning: they released a report on a day ending in "y"). People are noting the connection to the short selling --- but since this will be the 3rd or 4th time someone has very publicly done that, I don't see anybody shocked or outraged by it.

But this public ostracism you referred to --- specifically the notion that dropping vulnerabilities with 24 hours notice would reliably generate it --- is fictitious. I'm not sure how you can be a part of the vulnerability research community and believe that there is public shunning attached to dropping zero-days, since many of the best known people in the community have repeatedly done exactly that.


I somehow sense you have already made up your mind about the ethics of this, have your own - rather fixed - views of what the majority of researchers think of it, and are unwilling to listen to opposing arguments. I'll stop trying.


They had all the marketing material available and ready to go (and I bet that took more than 24 hours to make). The 24 hr notice is just an out against the usual accusation of publishing an exploit without giving notice. They sure well knew AMD couldn't even verify it in 24hrs, allowing them to get the full publicity while coming off as a reputable security firm.


It's not unheard of in the sense of never having happened, but it is a clear breach of ethics for a security researcher. (The term for not doing what these guys did is "responsible disclosure").


If you put 10 people who find and publish security vulnerabilities professionally in a room, I do not think you would secure agreement that this is a "clear breach of ethics". There are extremely well-known researchers who have made a point of not coordinating with vendors; vendors, historically, have been far more abusive than researchers.


But security researchers don't exist in a vacuum: they're part of larger society. If the security researcher subgroup has a code of ethics that diverges too far from the popular perception of what their code of ethics should be, I could see popular pressure to bring them into alignment (all the way up to using the legal system).

I'm not saying the non-security researcher users on HN have an opinion representative of the public as a whole, but this comment and a previous question asking another user what security research they've published may point to such an ethics disconnect between security researchers and the broader populace -- or simply a disregard for the concerns of the broader populace. I think it would be beneficial for security researchers (or any professional group) to listen to ethics concerns of the broader group they're a part of.

On another note, I would also assert that abusive actions by vendors do not excuse abusive actions by researchers (and vice-versa).


Public security researchers compete with state-sponsored research teams and organized crime syndicates. Both of the latter entities are better funded than even commercial vulnerability teams, and neither of the latter publish any vulnerability information. I have a hard time ever seeing public researchers as the bad guys in these stories.


He did say “should” disqualify someone from employment, which I read as “ought to.” Idealism maybe. But with black or gray hat research, you’re right.


No, disclosing vulnerabilities without disclosure does not in fact make you a "grey hat", much as vendors would like that to be so.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: