Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

24 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.


One difference between security researchers and "exploit creators", which is a term I think you just made up, is that exploit creators presumably release exploits.

Don't tell HD Moore or the Metapsloit team about this, though. They may cry themselves to sleep tonight.


Creation and release are two different things. They have created the exploits, or else AMD wouldn't be taking them seriously. They have also contributed more to the re-creation of those exploits by others than they have to security. So you can quibble over whether others use the exact jargon that you would have, but that doesn't change the underlying reality.


Every security researcher creates exploits, so I'm not really sure what the distinction you're trying to make is.


This. Especially with the disclaimer that others have noted:

> "we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"


You don't have to speculate. They admit having financial interests in the actual text of their report.


Vulnerability and Exploit are different.


Can you demonstrate a vulnerability without producing an exploit? You have to provide a poc to demonstrate it to others at least, no?

Two sides of the same coin


You can release the concept and description of a vulnerability without releasing an operational exploit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: