tptacek
an hour ago
AMD didn't deny it was a vulnerability; they denied it was in the scope of the bounty program.
Remember that at giant tech companies, the incentive is to pay out bounties --- there are people on the vendor's team whose performance is measured in part by how much the program pays out.
odyssey7
an hour ago
What hair is this splitting? The issue was that AMD allowed a known and serious security vulnerability to exist within their customers’ systems, for months, and acted with a lack of candor while doing so.
tptacek
an hour ago
It's not hair-splitting; it's central to the idea of a bug bounty. Too many people have weird ideas about what bug bounties are for.
Hizonner
an hour ago
Yeah, like the weird idea that those programs are intended to in some way reduce the number of exploitable bugs actually out there.
tptacek
38 minutes ago
That's in fact often not their core purpose!
JumpCrisscross
31 minutes ago
What is it?
Hizonner
23 minutes ago
... which is why the rest of us should give them, and those who operate them, zero respect.
Nobody but AMD gives a fuck about AMD's internal policies or motivations.
sakkura
an hour ago
They wanted to keep it quiet. As if they did not mind if it was exploited by those with access to international network links.