Quis renovatores renovat — who updates the updater?

  • Ledivin@lemmy.world
    link
    fedilink
    English
    arrow-up
    54
    ·
    edit-2
    12 hours ago

    Sounds like everyone should stop reporting vulnerabilities and start selling them 🤷‍♂️ great work, AMD, there’s absolutely no way this relatively small “cost saving” backfires!

  • Onomatopoeia@lemmy.cafe
    link
    fedilink
    English
    arrow-up
    56
    ·
    12 hours ago

    Haha, oh boy, between AMD and MS, I predict some zero-days in the near future from people like Paul (the researcher here) just selling the exploit.

    • NaibofTabr@infosec.pub
      link
      fedilink
      English
      arrow-up
      45
      ·
      11 hours ago

      Worse. It encourages selling them to the black market instead.

      The illicit market for newly discovered security vulnerabilities generally pays pretty well, especially if you can demonstrate implementation. The only reason it’s not a much bigger problem is that most security researchers have some moral compunctions and the professional desire to fix problems, not proliferate them.

      If the companies basically tell the security researchers to pound sand, that encourages making a living elsewhere.

    • bluGill@fedia.io
      link
      fedilink
      arrow-up
      2
      ·
      11 hours ago

      These days there’s so much slop in the world that 0day reports end up being worthless. The idea is sound, but far too many people are abusing the system and so they’re not worth having anymore.

      • corsicanguppy@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 hours ago

        The report is only because there’s a 0-day sploit. It’s not like some cogsucker can make it up and get paid.

        Okay so we’ll have to have a neutral third-party confirm them, but really that will have to happen now anyway since no one will trust AMD to pay their promises.

  • vatlark@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    edit-2
    11 hours ago

    I expect 10k is nothing compared to one of their salaries. I would expect zero days are worth at least an entire salary.