Profile picture
Dan Guido @dguido
, 11 tweets, 4 min read Read on Twitter
So this AMDflaws.com business... CTS Labs asked us to review their research last week, and sent us a full technical report with PoC exploit code for each set of bugs.
Regardless of the hype around the release, the bugs are real, accurately described in their technical report (which is not public afaik), and their exploit code works.
I initially responded to their request out of curiosity -- "Hey, do you want to see our new processor bugs before we release them?" "hell yes I do" -- but after their asks continued to grow billed them our week rate for the work.
I spent all morning talking to reporters, mostly to correct twitter hot takes. Yes, all the flaws require admin privs but all are _flaws_ not expected functionality.
You can find a measured take that includes my commentary on these vulnerabilities from @lorenzoFB @motherboard: motherboard.vice.com/en_us/article/…
Adding a FAQ based on the last 24 hours:
- "Tell me more about how you were paid"
"In a situation like this, would it be common for your firm to discuss disclosure with the vendor?"
Yes, and we did. I discussed pros/cons of various options with them and recommended that they report the vulnerabilities to a CERT.
"Were you made aware of the plans to go public?"
No.
"How did CTS Labs find you? What is your relationship to them?"
Mutual friend. No ongoing relationship.
"Do you have any financial position or interest in AMD or Intel stock?"
No.
If you're looking for clear, technical information about the flaws then see the blog we just published:
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to Dan Guido
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member and get exclusive features!

Premium member ($3.00/month or $30.00/year)

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!