Skip to main content

Nowhere is safe now that AMD has suffered its own Meltdown

Chaos reigns as Ryzenfall pits security researchers against each other

AMD Ryzen 5 2400G & Ryzen 3 2200G Review fingers motherboard
Bill Roberson/Digital Trends
Bill Roberson/Digital Trends

(in)Secure is a weekly column that dives into the rapidly escalating topic of cyber security.

On Tuesday, March 13, security firm CTS Labs announced the discovery of 13 flaws in AMD’s Ryzen and Epyc processors. The issues span four classes of vulnerabilities that include several major issues, such as a hardware backdoor into Ryzen’s chipset, and flaws that can completely compromise AMD’s Secure Processor, a chip that’s supposed to act as a “secure world” where sensitive tasks can be kept out of malware’s reach.

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

The lack of agreement means there’s no way to know when the next flaw will be exposed, who it will come from, or how it will be reported.

This revelation comes just months after the reveal of the Meltdown and Spectre flaws that impacted chips from AMD, Intel, Qualcomm, and others. AMD, whose chips were compromised by some Spectre flaws, came out of the fiasco relatively unscathed. Enthusiasts focused their anger on Intel. Though a handful of class-action lawsuits were filed against AMD, they’re nothing compared to the hoard of lawyers set against Intel. Compared to Intel, AMD seemed the smart, safe choice.

That made Tuesday’s announcement of flaws in AMD hardware even more explosive. Twitter-storms erupted as security researchers and PC enthusiasts argued over the validity of the findings. Still, the information provided by CTS Labs was independently verified by another firm, Trail of Bits, founded in 2012. The severity of the issues can be argued, but they do exist, and they compromise what some PC users had come to view as the last safe harbor.

The wild west of disclosure

The content of CTS Labs’ research would’ve generated headlines in any event, but the reveal’s punch was amplified by its surprise. AMD was apparently given less than 24 hours to response before CTS Labs went public, and CTS Labs has not gone public with all technical details, instead choosing to share them only with AMD, Microsoft, HP, Dell, and several other large companies.

Many security researchers cried foul. Most flaws are disclosed to companies earlier, alongside a timeframe to respond. Meltdown and Spectre, for instance, was disclosed to Intel, AMD, and ARM on June 1 of 2017 by Google’s Project Zero team. An initial 90-day window to fix the problems was later extended to 180 days, but ended ahead of schedule when The Register published its initial story on Intel’s processor flaw. CTS Labs’ decision not to offer prior disclosure has caused speculation that it had another, more malicious motive.

AMD Flaws Overview

CTS Labs defended itself in a letter from Ilia Luk-Zilberman, the company’s CTO, published on the AMDflaws.com website. Luk-Zilberman takes issue with concept of prior disclosure, saying “it’s up to the vendor if it wants to alert the customers that there is a problem.” That’s why you rarely hear of a security flaw until months after it was uncovered.

Worse, says Luk-Zilberman, it forces a game of brinkmanship between the researcher and the company. The company might not respond. If that happens, the researcher faces a grim choice; keep quiet and hope no one else finds the flaw, or go public with the details of a flaw that has no available patch. Cooperation is the goal, but the stakes for both researcher and company encourage defensiveness. The question of what’s proper, professional, and ethical often collapses into petty tribalism.

Where’s the bottom?

The industry standard for disclosing a flaw doesn’t exist and, in its absence, chaos reigns. Even those who believe in disclosure don’t agree on details, such as how long a company should be given to respond. The lack of agreement means there’s no way to know when the next major flaw will be exposed, who it will come from, or how it will be reported.

It’s like strapping on a life vest as a ship sinks into frigid waters. Sure, the vest is a good idea, but it’s not enough to save you anymore.

Cyber security is a mess, and it’s a mess that’s taken its toll on each of us. While alarming, the new flaws in AMD processors — like Meltdown, Spectre, Heartbleed, and so many others before — will be soon be forgotten. They must be forgotten.

After all, what other choice do we have? Computers and smartphones have become mandatory for participation in modern society. Even those who don’t own them must use services that rely on them.

Every piece of software and hardware we use is, apparently, riddled with critical flaws. Even so, unless you decide to abandon society and build a cabin in the woods, you must use them.

Normally, I’d like this column to end on practical advice. Use strong passwords. Don’t click on links that promise free iPads. That sort of thing. Such advice remains true, but it feels like strapping on a life vest as a ship sinks in frigid arctic waters. Sure. The life vest is a good idea. You’re safer with it than without — but it’s not enough to save you anymore.

Editors' Recommendations

Matthew S. Smith
Matthew S. Smith is the former Lead Editor, Reviews at Digital Trends. He previously guided the Products Team, which dives…
Best monitor deals: Gaming, office, curved, OLED and more
Dell UltraSharp 27 4K PremierColor Monitor

Whether you're grabbing yourself one of these desktop computer deals or just want to upgrade to a new monitor, you'll be happy to know that the market has really boomed in the past few years. Not only have monitors gotten cheaper, but they're also packed with more features and specs for the same price. Also, it's worth noting that even if you're running a laptop, connecting a second screen can be really handy for work or even gaming, so don't completely ignore these deals if you are using a laptop.

As such, now is a great time to pick a monitor up since even the best monitors have some sort of deal on them, which is why we've gone out and collected our favorite ones below.
Best monitor deals

Read more
Best MacBook deals: Get an Air for $605 and save on M3 MacBook Pro
A MacBook Pro M2 sits on a wooden table with a nice bokeh background.

Apple has been in the laptop game for quite a while now, and its MacBook Air and MacBook Pro lineups are some of the best laptops on the market, especially since Apple has started using its own chips. Of course, you do have to pay a premium for the brand name and the product, and if you're thinking of grabbing one of these, then you may need to rely on some solid Apple deals to get you through. That's why we've scoured some of the biggest retailers online and found the best deals we could, whether you want an early-model MacBook Air M1 or the latest M3 MacBook Pro. That said, if you're not really feeling any of these MacBooks, be sure to check out these other great laptop deals instead.
Best MacBook Air (M1) deals

The Apple MacBook Air (M1) started a seismic shift for Apple being the first of its Airs to have an Apple-based processor. We took a look at the differences between the M2 and M1 and the M1 is still looking pretty great. It's also a touch nearer to affordable than anything else here. Fast yet fanless so it's silent to use, you gain an 18-hour battery life, a gorgeous looking 13.3-inch Retina display along with all the effortless style you'd expect from an Apple device. These laptops are best for students or those who want something stylish yet reasonably powerful to use on the move. Nowadays, deals are becoming a little harder to come by unless you're willing to consider a refurbished/renewed model.

Read more
Best gaming laptop deals: Alienware, Razer, Asus and more
An Alienware m16 gaming laptop in use on a desk, playing Baldur's Gate III.

Gaming can be a lot of fun, but if you're the sort of person who doesn't want to deal with a big gaming desktop, then going for a gaming laptop makes a lot of sense. Of course, you aren't going to get as much power under the hood as you would with a desktop, and it might cost a bit more, but you do get a lot of mobility and an included screen in the process. Either way, modern gaming laptops have become really great, and even the budget-oriented stuff can play some of the best PC games out there.

To that end, we've gone out and collected some of our favorite gaming laptop deals out there. On the other hand, if you don't want something that yells "gaming laptop," check out some of these other laptop deals that include more traditional-looking laptops with some gaming specs.
IdeaPad Gaming 3 gaming laptop -- $617, was $950

Read more