• isekaihero@ani.social
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 months ago

    The obvious solution to this is to not seek the bug bounty. The next time a critical security vulnerability is found, sell it to the highest bidder. I’m sure there are black hats out there willing to pay the money that the megacorp refuses to pay out.

    • riko@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      2 months ago

      That is essentially the behavior AMD is incentivizing here.

    • Jason2357@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      I feel for people wanting to be security researchers with a conscience. They used to get thrown in jail or hit with lawsuits. Things progressed to where they could get a tiny fraction of the black market value as a bug bounty, and possibly even make a basic living doing that, but we are probably headed back in the other direction.

      Meanwhile, black hats are sitting in a resort pool somewhere spending the half million some authoritarian regime paid them for a simmilar exploit, trying to drink enough all-inclusive booze to avoid thinking of the people getting their fingernails pried off in some goulag after getting exposed via said exploit.

    • rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      The updated post contains the full story, and it goes as follows: Back in February, when AMD asked Paul to bring down the blog post temporarily, the company said it would issue a standard CVE, fix the software, and attribute the findings to him, though a bounty payment was out of the question. Paul agreed (a decision he now regrets), though he asked what kind of timeline AMD would follow, suggesting the industry-standard 90-day window until he posted the public disclosure again.

      AMD replied saying that it would “likely need a longer embargo, as additional tools beyond Ryzen Master appear[ed] to be impacted and [would] need releases.” That was an interesting statement in several ways: first, it raises the question exactly why AMD would need so long to publish what was seemingly a one-character fix, replacing “http” with “https” in the code. Second, if the issue was bad enough to require so long to solve, then arguably Paul’s work would merit some recompense. Third, as Paul pointed out, if this issue looked this pressing, why didn’t it have a higher priority?

      Nevertheless, he ended up agreeing on a 100-day window, and asked AMD the equivalent of “wassup?” before the clock ticked its last tock, only to be asked for extra time again, being told that “multiple tools are affected by [the bug]”, and that “[AMD’s] customers request additional time once [the fixes] are made available.” Eventually, AMD reached out stating that a fix would be ready on June 9, totaling 124 days after the initial finding.

      “the company said it would issue a standard CVE, fix the software, and attribute the findings to him, though a bounty payment was out of the question.”

      Nah, they should pay him…

      • innermachine@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        2 months ago

        For those that don’t read the article - Paul AGREED to no payment, and later regret it. Why should amd pay? They made it clear their policy doesn’t cover MITM attacks and so there is no bounty available for this vulnerability. Amd had and has no obligation to make the pay out, ESPECIALLY when the researcher agreed to no pay out!

        • rumba@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          They told him that paying him was out of the question and he said ohhh

          They can fucking pay him.

          • innermachine@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            arrow-down
            1
            ·
            2 months ago

            Reading comprehension not your strong suit? Or just raging on the title without clicking the link?

            • rumba@lemmy.zip
              link
              fedilink
              English
              arrow-up
              0
              arrow-down
              1
              ·
              2 months ago

              Hey troll, that’s from the fucking link. go read it yourself. and welcome to my blocklist

              • innermachine@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                2 months ago

                Hey 🤡 did u read the part where AMD doesn’t offer reward for MITM attacks? And that this vulnerability could not be exploited? Think I give a fuck if I’m on ur block list? Keep isolating urself in ur own little echo chamber buddy like I give a fuck 😂

  • 🇨🇦 tunetardis@piefed.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 months ago

    Researcher commenting on the patch:

    he remarks that the software only checks the validity of the downloaded file using the ancient CRC32 hash that isn’t considered cryptographically secure anymore

    I have to respect the researcher for his incredibly charitable wording here. CRC32 is not even remotely crypto. That’s never been its purpose, and using it for digital signing is patently insane!

    I fear I would have had a much shorter temper after what he’s been through, and yet here he is keeping his cool and his criticism constructive. Good on him.

  • iturnedintoanewt@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    2 months ago

    Holy crap. I’d say not to buy AMD if you value your security (i have an AMD CPU and the Deck too). You already know the next vulnerability they’re going to be the last ones to find out. In the news, probably.

    • Peter1986C@nord.pub
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      The Steam Deck does run Linux right? Generally that means the used drivers are not written by AMD and also do not have an auto-updater from AMD. The deck is supposed to update through it’s OS’es package manager and supposedly has the Mesa and Linux Foundation drivers in use.

      • BlackLaZoR@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        AMD does contribute to MESA and kernel driver. It’s all open source, but they do lot of heavy lifting regardless

  • kamen@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    The impulsive guy in me is thinking that I should cancel AMD over something like this while the rational one remembers that (at least for non-Apple PCs) it’s basically a duopoly and if I cancel the other player over something stupid that they do, I’d be out of choices.

    What do you guys think?

    • innermachine@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      2 months ago

      Do yourself a favor and actually read the article. Not saying AMD is in the right here, but they aren’t in the wrong for not paying Paul when he agreed to no pay out.

  • kuhli@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    2 months ago

    Y’all really need to read past the headline:

    the bug that Paul found seemingly wouldn’t be triggered anyway, as the relevant section of the code wasn’t being called to begin with

    • rustydrd@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      I guess it’s one of those “justifiable but unwise” sort of things. If your company is doing a bug bounty program to stay on top of security vulnerabilities, what you don’t want is to create the perception that the work of devs who look for these vulnerabilities isn’t appreciated, for example, by skimping on bounties over technicalities.

      Paying the 10k doesn’t ruin the company and allows them to fix a section of code that may become a vulnerability in the future. Not paying the 10k saves them 10k at the price of the devs’ trust that keeps this program effective. From a financial point of view, this is some very poor decision making.

    • AAA@feddit.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      If it’s in the code, it’s a bug. If it’s not used, then remove it entirely. Everything in the code should be treated as operational.