People here seems to be mentioning short sellers being connected to this research as if there's some sinister collusion going on.
This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company
For example, a short seller last year revealed (through extensive research), that Valeant Pharmaceuticals was stuffing its channels and faking its finances. He placed a huge sort sell and went public with the damaging info - tanking the stock from $270 to $12 and made a ton of profit off of it: https://www.nytimes.com/2017/06/08/magazine/the-bounty-hunte...
Without this incentive, why would anyone bother to reveal damaging info? You're placing your self as a target with no reward. The payment is the natural balance of the market.
So yes, this research firm is connected w a hedge fund, and they have a very vested interest. But that doesn't make their claim untrue
It's also a huge incentive to overstate the severity. Their goal is to profit off the panic they can produce, so every statement they make is likely heavily biased in that direction.
That said, I don't mind that these "research" organizations exist. Only bothers me when they put the general public at risk (or attempt to) for their own gain.
The point is the counter balance the other side - companies have an incentive to overstate their upside and understate their risk.
Short sellers want the opposite. So they both present their best cases and let the public decide, much like how lawyers will defend their own clients to the last breath regardless of the amount of evidence against them
I disagree. AMD needs to maintain it's reputation over time. Short sellers make their profit over a few hours/days and don't care if they are proven wrong.
So, AMD has vastly more incentive to be accurate than short sellers.
Pity that vast incentive didn't seem to work out when they promoted all these chips as having "Firmware Trusted Platform Module", "Secure Encrypted Virtualization", "AMD Secure Processor", and "AMD Secure OS" as features.
AMDs incentive, like any corporation, is to maximise shareholder value. Same as any tiny little security research firm. If a research firm can maximise their profit buy discovering vulnerabilities and shorting stock before disclosing them, is that any ethically worse than a chip company rushing out flawed hardware with big flashy marketing bullet points claiming how secure they are?
(I'm not saying short-selling chip vendor stocks on the back of vulnerabilities is a way I'd choose to make a living, but surveillance capitalism doesn't seem an "ethically better" industry to work in either...)
As to ethics that's mostly irrelevant to this discussion. Both sides could have ethical behavior, I am simply pointing out which side has the larger incentives to exaggerate. After all the stock could drop and a short seller could still lose money. They need the stock to drop a lot even over a minor issue.
While the dollar value of AMDs incentive is without doubt larger - the existential value of the smaller amount incentivising the researcher is likely more motivating...
On an individual level, it's much less I'd think. Inciting a panic could be life changing amounts of money for the researchers, paid out by the hedge fund returns.
AMD isn't going to crash and burn over these flaws anymore than Intel (at 5 year high) did.
More and more lately I'm leaning towards the, "responsible disclosure is a bunch of crap" camp. You have to be "in" to get the news. Even if you're "in" security people love to play info war power games and withhold things because it tickles their jimmies, etc. And don't forget, you're deliberately keeping a vulnerability secret from consumers during a long period where you have no idea who else knows about it. If I'm a "user" or 3rd party and there's a critical vuln in some system I depend on, I want to know that I shouldn't use it or that I should take extra caution or whatever rather than being clueless in all in the name of the vendor's image.
This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security.
It's sad to see people arguing for a return to those norms, especially since the rejection of them correlates with a renaissance in our understanding how to secure software.
It looks like the short notice in this case is not intended to force a timely fix, but to prevent it. They are hoping to cause as much of damage to the company as possible both directly and indirectly through its customers so they can profiteer from it.
I'd say that the intent makes this qualitatively different to what I'd consider legitimate disclosure.
The flip side to that is to ask whether AMD have been "profiteering" from their customers by deceiving them about the security of their products?
It's not like their marketing copy makes accurate claims like:
"We're reasonably sure our Firmware Trusted Platform Module is trustworthy, but we ran out of time to pentest it properly before we shipped it."
or
"Ryzen features Probably-Secure Encrypted Virtualization! Our interns couldn't break it in a afternoon of trying! The data looks random enough to us..."
How much does "the intent" of their marketing copy and claims come into play?
> It's sad to see people arguing for a return to those norms
Where do you see anyone arguing for that? Or is it just a strawman? What I see is not people arguing against disclosure but people arguing for disclosure with an embargo longer than a day. You're going to have a hard time proving that one day is a norm, or that it correlates with a renaissance in securing software. Your response looks much more like circling the wagons when a member of your tribe is criticized.
If some security researchers are currently choosing immediate highly publicised disclosure and short selling because it's the most profitable path for them - perhaps companies should reconsider their default/expected response to vendor-privileged-disclosure?
It's not like AMD set their chip prices based on "ethics" or "duty to the public". As "the public" I'd prefer a Ryzen 1900X to sell for $150 rather than $500 - It's just a bunch of sand after all (plus some intellectual effort). I don't think AMD get to choose their pricing model but then complain about how security companies price/sell their intellectual work...
Don't sue people if they publish vulnerabilities without any notification to the vendor, as long as they never overstepped and exploited it themselves.
> Having a financial incentive to mess up AMD might explain why they only gave 24 hours' warning, though.
A good way for companies to prevent this is to have a generous bug bounty program. Money is still transferred from the shareholders to the researchers, but then the company can impose conditions like delaying public disclosure for a reasonable time to prepare a fix.
If it's actually someone attempting to make money on a short or to benefit from a working relationship with a competitor, then a bug bounty program does nothing. No one can run a bounty program that pays out anywhere near as much as the information is actually worth to an adversary. Bug bounties work to engender a bit of good will among researchers and to provide some incentive to an otherwise neutral party to play ball. They don't mean shit to a hedge fund or a competitor in a multi-billion dollar industry.
> Not unless the bounties are large enough to attract the attention of a hedge fund.
Which they should be if the alternative is a much larger loss to the company's share value. The shareholders come out ahead to pay five million on a bug bounty if the alternative is to lose a billion dollars in market cap.
I'm not a finance expert, but my very lay person understanding of how financial markets work tells me that those would have to be some rather huge bounties. See e.g., the effect on Intel from earlier this year:
It's not their problem. There's no obligation for them to give any warning at all. They can just go public, short the stock, and watch it fall. The warning is just a polite thing to do
That's fine, but it doesn't change the fact that the possibility (likelyhood?) of financial gain affects the authors credibility. Especially since it is already strained by other issues with this disclosure.
It seems to me that disclosing vulnerabilities is in a different category from disclosing fraud. In the latter case, the only entities that suffer materially is the fraudulent organization and its investors, in the former you have the additional potential to expose all users of the vulnerable software to risk.
This is the entire point of short selling, and SEC encourages this type of activism. It allows people who can provide expert knowledge to profit off a trade if it can reveal damaging and legitimate information about a company
For example, a short seller last year revealed (through extensive research), that Valeant Pharmaceuticals was stuffing its channels and faking its finances. He placed a huge sort sell and went public with the damaging info - tanking the stock from $270 to $12 and made a ton of profit off of it: https://www.nytimes.com/2017/06/08/magazine/the-bounty-hunte...
Without this incentive, why would anyone bother to reveal damaging info? You're placing your self as a target with no reward. The payment is the natural balance of the market.
So yes, this research firm is connected w a hedge fund, and they have a very vested interest. But that doesn't make their claim untrue