Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It looks like the short notice in this case is not intended to force a timely fix, but to prevent it. They are hoping to cause as much of damage to the company as possible both directly and indirectly through its customers so they can profiteer from it.

I'd say that the intent makes this qualitatively different to what I'd consider legitimate disclosure.



The flip side to that is to ask whether AMD have been "profiteering" from their customers by deceiving them about the security of their products?

It's not like their marketing copy makes accurate claims like:

"We're reasonably sure our Firmware Trusted Platform Module is trustworthy, but we ran out of time to pentest it properly before we shipped it."

or

"Ryzen features Probably-Secure Encrypted Virtualization! Our interns couldn't break it in a afternoon of trying! The data looks random enough to us..."

How much does "the intent" of their marketing copy and claims come into play?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: