Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.
Who works for CTS-Labs? Attaching your name to a company like that should disqualify you from any future jobs in the security space.
"Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.
> "Unheard of"? People have dropped serious vulnerabilities with _zero_ warning before.
Could you point me to an example of a zero warning disclosure that exposed a large amount of users without first attempting to coordinate with the responsible party?
I'm not saying the non-security researcher users on HN have an opinion representative of the public as a whole, but this comment and a previous question asking another user what security research they've published may point to such an ethics disconnect between security researchers and the broader populace -- or simply a disregard for the concerns of the broader populace. I think it would be beneficial for security researchers (or any professional group) to listen to ethics concerns of the broader group they're a part of.
On another note, I would also assert that abusive actions by vendors do not excuse abusive actions by researchers (and vice-versa).
Individuals sometimes do this, security companies very rarely - and both are shunned by the infosec community at large when they do so, as this is very unethical behaviour.
They registered the domain a couple of weeks ago - why give AMD only 24 hours notice?
In this case it does seem highly likely there is some stock market skullduggery afoot.
Just take a look on twitter at what prominent members of the community are saying - they are not impressed with this behaviour. I'm also a member of that community, and hold the same view.
The vast majority of the infosec community promote coordinated disclosure.
The CTS-Labs people are taking shit from vulnerability research twitter for overhyping the findings (meaning: they released a report on a day ending in "y"). People are noting the connection to the short selling --- but since this will be the 3rd or 4th time someone has very publicly done that, I don't see anybody shocked or outraged by it.
But this public ostracism you referred to --- specifically the notion that dropping vulnerabilities with 24 hours notice would reliably generate it --- is fictitious. I'm not sure how you can be a part of the vulnerability research community and believe that there is public shunning attached to dropping zero-days, since many of the best known people in the community have repeatedly done exactly that.
As am AMD system owner, I would much prefer that big flaws were disclosed in a coordinated manner with AMD - giving them a fair chance to verify and find a solution, rather than giving bad actors a head start.
[1] I'm partially recalling a fix, on Facebook I think, that was implemented within a few hours of reporting; it was ac testing API that got exposed. Different field, of course.
Follow the money.