Wednesday, March 14th 2018
Linus Torvalds Slams Security Researchers Without Taking Names
Linus Torvalds has, without taking names, slammed the direction in which the IT security industry is going. The timing of Torvalds' comments is key. They come on a day when CTS-Labs published a press-release chronicling what they claim to be 13 critical security vulnerabilities with AMD "Zen" CPU microarchitecture. "It looks like the IT security world has hit a new low," Torvalds begins. "If you work in security, and think you have some morals, I think you might want to add the tag-line: "No, really, I'm not a whore. Pinky promise" to your business card. Because I thought the whole industry was corrupt before, but it's getting ridiculous," he continues. "At what point will security people admit they have an attention-whoring problem?"
CTS-Labs classified their 13 new discoveries into four categories, complete with a Meltdown/Spectre-esque graphics package, infographics, and a YouTube video with amateur-level green-screen stock footage behind the only 3 people the company has on its payroll. Their disclosures invited scorn from the public, particularly for not following the unwritten guideline of IT-sec industry that you have to give hardware/software manufacturers at least 90 days to respond/mitigate your findings before taking your work public. CTS-Labs gave AMD barely 24 hours. Some of the more skeptic voices suggest that these disclosures are part of a purpose-built stock shorting scheme that's currently engaged in devaluing AMD.AMD itself took an exception to this guerrilla-ambush tactic adopted by the researchers. "This company was previously unknown to AMD and we find it unusual for a security firm to publish its research to the press without providing a reasonable amount of time for the company to investigate and address its findings." AMD stock performance approaching closing-bell Tuesday suggests that the company's investors are giving it the benefit of doubt, that its corporate-communications and investor-relations teams are on overdrive, and that it would be prudent to hear what the company has to say. At least now that it has the investors' and public's attention, we won't hear of incidents like its senior execs dumping company stock, something that can't be said for AMD's biggest competitor.
Source:
Linus Torvalds (Google+)
CTS-Labs classified their 13 new discoveries into four categories, complete with a Meltdown/Spectre-esque graphics package, infographics, and a YouTube video with amateur-level green-screen stock footage behind the only 3 people the company has on its payroll. Their disclosures invited scorn from the public, particularly for not following the unwritten guideline of IT-sec industry that you have to give hardware/software manufacturers at least 90 days to respond/mitigate your findings before taking your work public. CTS-Labs gave AMD barely 24 hours. Some of the more skeptic voices suggest that these disclosures are part of a purpose-built stock shorting scheme that's currently engaged in devaluing AMD.AMD itself took an exception to this guerrilla-ambush tactic adopted by the researchers. "This company was previously unknown to AMD and we find it unusual for a security firm to publish its research to the press without providing a reasonable amount of time for the company to investigate and address its findings." AMD stock performance approaching closing-bell Tuesday suggests that the company's investors are giving it the benefit of doubt, that its corporate-communications and investor-relations teams are on overdrive, and that it would be prudent to hear what the company has to say. At least now that it has the investors' and public's attention, we won't hear of incidents like its senior execs dumping company stock, something that can't be said for AMD's biggest competitor.
27 Comments on Linus Torvalds Slams Security Researchers Without Taking Names
EDIT: Should clarify I am speaking legally, not ethically.
However we do know their domains were registered on GoDaddy.com
Any transaction will leave trails. unless they are at the level of shadow government.
It was Intel or an executive working in the interest of Intel. We all know how much they have to lose with Epyc this year.
That Intel statement at the end of GN video. Yeah, like Intel is going to admit it even if they did have hands in it lol
I doubt intel has anything major to do with this either.
This is someone who have betted on amd stocks going further down and when they shot up because of ryzen and so on they had to manipulate.
funny what if the last business/person/item/sports team you talked shit about right here on these forums comes after you?
don't kill the messenger
Over here, we can make up our own minds about what's credible and what's not - something people are actually capable of as one can read clearly in the article.
I hope AMD nails their hides to a post.