Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is how the whole industry ran in the mid-1990s. There were secret vendor lists that the cool kids got to be on. If you didn't have the right friends, you were shut out. Vendors took their sweet time getting patches out, because their preferred customers were all read in and had workarounds in place. It was a shitty way to organize an industry, and it fell apart with Bugtraq and full-disclosure security.

It's sad to see people arguing for a return to those norms, especially since the rejection of them correlates with a renaissance in our understanding how to secure software.



It looks like the short notice in this case is not intended to force a timely fix, but to prevent it. They are hoping to cause as much of damage to the company as possible both directly and indirectly through its customers so they can profiteer from it.

I'd say that the intent makes this qualitatively different to what I'd consider legitimate disclosure.


The flip side to that is to ask whether AMD have been "profiteering" from their customers by deceiving them about the security of their products?

It's not like their marketing copy makes accurate claims like:

"We're reasonably sure our Firmware Trusted Platform Module is trustworthy, but we ran out of time to pentest it properly before we shipped it."

or

"Ryzen features Probably-Secure Encrypted Virtualization! Our interns couldn't break it in a afternoon of trying! The data looks random enough to us..."

How much does "the intent" of their marketing copy and claims come into play?


> It's sad to see people arguing for a return to those norms

Where do you see anyone arguing for that? Or is it just a strawman? What I see is not people arguing against disclosure but people arguing for disclosure with an embargo longer than a day. You're going to have a hard time proving that one day is a norm, or that it correlates with a renaissance in securing software. Your response looks much more like circling the wagons when a member of your tribe is criticized.


I agree, but I am curious if you have any suggestions on how we should be handling disclosure?


If some security researchers are currently choosing immediate highly publicised disclosure and short selling because it's the most profitable path for them - perhaps companies should reconsider their default/expected response to vendor-privileged-disclosure?

It's not like AMD set their chip prices based on "ethics" or "duty to the public". As "the public" I'd prefer a Ryzen 1900X to sell for $150 rather than $500 - It's just a bunch of sand after all (plus some intellectual effort). I don't think AMD get to choose their pricing model but then complain about how security companies price/sell their intellectual work...


Don't sue people if they publish vulnerabilities without any notification to the vendor, as long as they never overstepped and exploited it themselves.


For what it’s worth, this is a fierce debate that goes back decades. There is widespread disagreement among professionals in the field.


But what if we give the list a really cool name like gazorpazorp?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: