Y’all really need to read past the headline:
the bug that Paul found seemingly wouldn’t be triggered anyway, as the relevant section of the code wasn’t being called to begin with
Even if it was that simple, this is still a vulnerability that is basically a time bomb. The day that code would have been triggered would have been disastrous.
But this isn’t new, bug bounties tend to have terms as strict as they can to deny you the bounty while they obviously end up fixing issues that don’t qualify for the bounty. All because of reason X or Y that turns out to be a subjective interpretation of a vague enough eligibility requirement.
If it’s in the code, it’s a bug. If it’s not used, then remove it entirely. Everything in the code should be treated as operational.
Pretty sure ur the only commentator here that actually opened the link LMFAO
Does AMD want their own Nightmare-Eclipse or what. And that researcher went rogue because MS has the habit to not credit researchers and claiming that vulnerabilities are not vulnerabilities while quietly fixing them.
They could have worse. The extreme geeks who worked as engineers for AMD pushed to open source their firmware, PSP, everything at one point.
Can you imagine Nightmare but with PSP or Intel ME? It would be EPYC™
Researcher commenting on the patch:
he remarks that the software only checks the validity of the downloaded file using the ancient CRC32 hash that isn’t considered cryptographically secure anymore
I have to respect the researcher for his incredibly charitable wording here. CRC32 is not even remotely crypto. That’s never been its purpose, and using it for digital signing is patently insane!
I fear I would have had a much shorter temper after what he’s been through, and yet here he is keeping his cool and his criticism constructive. Good on him.
Although it is true that they now fully use HTTPS, the claim about signature verification is untrue; they only perform a CRC-32 check on the downloaded executable, which is not cryptographically secure.
This is the wording from the blog post. Tom’s Hardware just rephrased it very poorly. (see e.g. https://www.reddit.com/r/hardware/comments/1ixgas1/articles_from_tomshardwarecom_should_be_banned/)
Do you really need signing if you’re using HTTPS though?
HTTPS is privacy in transit. It has no say into what’s being downloaded.
A drug dealer with a heavily armed escort delivers a package of white powder. New problem: is it cocaine, cleaning detergent, anthrax, or some mixture of the former?
I suppose if the only way to obtain the patch were through an automated download from the AMD website, the authentication through the site certificate would be better than nothing. But this is a security patch, and I think the researcher is right in pointing out that the bar needs to be higher?
My version of questioning this is if the same source is providing both the file and the hash, does it matter how hard it is to fake the hash? It could just generate a new hash for the fake file, couldn’t it?
Holy crap. I’d say not to buy AMD if you value your security (i have an AMD CPU and the Deck too). You already know the next vulnerability they’re going to be the last ones to find out. In the news, probably.
Under Linux, AMD GPU is the only sane solution tho, due to open source drivers. And Intel CPUs have history of cookin hard.
It’s not. RISC-V and ARM exist. You can buy laptops based on either of these architectures for a very reasonable price, compared to Intel and AMD’s x86 offerings.
Of course, that means no AAA gaming, for the most part at least. But then again, who even plays AAA games these days?
But then again, who even plays AAA games these days?
Err many people? And Linux gaming is on the rise too.
Linux gaming is perfectly fine.
ARM gaming isn’t. Let alone RISC-V gaming. Not AAA at least. You can play pretty much all older and lighter games on anything starting from Snapdragon 8 Gen 2. Which is perfectly fine for me personally. However, if you want to play more demanding titles, ARM isn’t gonna cut it at the moment.
Err many people?
Well, many people smoke too. Could not care less about it.
But then again, who even plays AAA games these days?
Gaming industry is way bigger than movie industry. Almost everyone plays games.
Steam alone has like 40 million concurrent players right now.
Gaming industry is way bigger than movie industry. Almost everyone plays games.
Most money goes into mobile money traps, though.
Consumer ARM hardware mostly needs customized images for each board. Plus, depending on your CPU manufacturer you’ll be stuck on an ancient kernel version to get full functionality.
And the performance/watt is not that exceptional.
those are not consumer friendly
As opposed to Intel, AMD, and Nvidia being super consumer friendly?
sadly yes, until this year
RISC-V and ARM exist. You can buy laptops based on either of these architectures for a very reasonable price, compared to Intel and AMD’s x86 offerings.
Have fun dealing with that Device Tree bullshit because hardware autodetection is so 1998.
It’s all a matter of [relatively minor] investment into R&D. Would you prefer being a subject of Intel and AMD’s perpetual x86 duopoly forever?
They can set whatever prices they like, because nobody else is allowed to touch their little instruction set. With the tiny exception of a Chinese company whose best CPU is the equivalent of an 8th gen i5.
You’ll pay whatever they demand or you won’t have a PC. Yeah, this is so much fun compared to ‘dealing with ARM bullshit’.
This entire architecture has lived way past its time. Intel and AMD being utter garbage corporations did not help in the least.
Let it die along with those two dumpster fires, and move on.
Would you prefer being a subject of Intel and AMD’s perpetual x86 duopoly forever?
That’s not how patents work. x64 patents lapse sometime THIS YEAR. Everyone can make 64bit x86 CPUs.
Ok, so the alternative is buying Intel/Nvidia. Surely they’ve never done anything problematic, so this is a good plan.
No no no. You buy half an intel chip, and half of an AMD chip. Then mush them together!
The Steam Deck does run Linux right? Generally that means the used drivers are not written by AMD and also do not have an auto-updater from AMD. The deck is supposed to update through it’s OS’es package manager and supposedly has the Mesa and Linux Foundation drivers in use.
AMD does contribute to MESA and kernel driver. It’s all open source, but they do lot of heavy lifting regardless
The woman in the stock photo looks like she’s about to pilot an X-Wing.
Researches should publish after 90 days. That would solve the problem.
Another proof mega corporations are the equivalent of a selfish sociopath, unreliable, can’t be trusted and must be kept under scrutiny at all times
The impulsive guy in me is thinking that I should cancel AMD over something like this while the rational one remembers that (at least for non-Apple PCs) it’s basically a duopoly and if I cancel the other player over something stupid that they do, I’d be out of choices.
What do you guys think?
Honestly? Fuck technology. I’m probably just in a bad mood, but that’s how I feel right now. Get rid of all of it. If you can’t figure it out on an abacus, you don’t really need to know it!
Same. Unless I live like a hermit in the woods, I am definitely using, directly or not, something (many things) made by a company that has done unforgivable shit. And even if I personally decide “to hell with all this, I can survive just fine”, who will be there to stop them from destroying the whole forest I am supposedly in? Definitely not me
This does not make things all right as they stand, but it does mean quitting the game is not an option
Do yourself a favor and actually read the article. Not saying AMD is in the right here, but they aren’t in the wrong for not paying Paul when he agreed to no pay out.
If anyone could provide an AMD email to ask for a statement concerning this issue, that would be nice.
I don’t think a statement is really needed here, this wasn’t a vulnerability, the code was never called. Even if the code were called, the $10,000 bounty is for a different type of bug entirely too
so stacking vulnerabilities is a thing
if the code exists it can be called
this is a valid bug and it’s silly to rule lawyer something like this
so good job amd, you are ‘actually’ right,
this totally won’t cost you in the long run at all
god damn do lawyers and business majors need to stop making tech decisions










