Skip to main content

Nowhere is safe now that AMD has suffered its own Meltdown

Chaos reigns as Ryzenfall pits security researchers against each other

AMD Ryzen 5 2400G & Ryzen 3 2200G Review fingers motherboard
Bill Roberson/Digital Trends
Bill Roberson/Digital Trends

(in)Secure is a weekly column that dives into the rapidly escalating topic of cyber security.

On Tuesday, March 13, security firm CTS Labs announced the discovery of 13 flaws in AMD’s Ryzen and Epyc processors. The issues span four classes of vulnerabilities that include several major issues, such as a hardware backdoor into Ryzen’s chipset, and flaws that can completely compromise AMD’s Secure Processor, a chip that’s supposed to act as a “secure world” where sensitive tasks can be kept out of malware’s reach.

The lack of agreement means there’s no way to know when the next flaw will be exposed, who it will come from, or how it will be reported.

This revelation comes just months after the reveal of the Meltdown and Spectre flaws that impacted chips from AMD, Intel, Qualcomm, and others. AMD, whose chips were compromised by some Spectre flaws, came out of the fiasco relatively unscathed. Enthusiasts focused their anger on Intel. Though a handful of class-action lawsuits were filed against AMD, they’re nothing compared to the hoard of lawyers set against Intel. Compared to Intel, AMD seemed the smart, safe choice.

That made Tuesday’s announcement of flaws in AMD hardware even more explosive. Twitter-storms erupted as security researchers and PC enthusiasts argued over the validity of the findings. Still, the information provided by CTS Labs was independently verified by another firm, Trail of Bits, founded in 2012. The severity of the issues can be argued, but they do exist, and they compromise what some PC users had come to view as the last safe harbor.

The wild west of disclosure

The content of CTS Labs’ research would’ve generated headlines in any event, but the reveal’s punch was amplified by its surprise. AMD was apparently given less than 24 hours to response before CTS Labs went public, and CTS Labs has not gone public with all technical details, instead choosing to share them only with AMD, Microsoft, HP, Dell, and several other large companies.

Many security researchers cried foul. Most flaws are disclosed to companies earlier, alongside a timeframe to respond. Meltdown and Spectre, for instance, was disclosed to Intel, AMD, and ARM on June 1 of 2017 by Google’s Project Zero team. An initial 90-day window to fix the problems was later extended to 180 days, but ended ahead of schedule when The Register published its initial story on Intel’s processor flaw. CTS Labs’ decision not to offer prior disclosure has caused speculation that it had another, more malicious motive.

AMD Flaws Overview

CTS Labs defended itself in a letter from Ilia Luk-Zilberman, the company’s CTO, published on the AMDflaws.com website. Luk-Zilberman takes issue with concept of prior disclosure, saying “it’s up to the vendor if it wants to alert the customers that there is a problem.” That’s why you rarely hear of a security flaw until months after it was uncovered.

Worse, says Luk-Zilberman, it forces a game of brinkmanship between the researcher and the company. The company might not respond. If that happens, the researcher faces a grim choice; keep quiet and hope no one else finds the flaw, or go public with the details of a flaw that has no available patch. Cooperation is the goal, but the stakes for both researcher and company encourage defensiveness. The question of what’s proper, professional, and ethical often collapses into petty tribalism.

Where’s the bottom?

The industry standard for disclosing a flaw doesn’t exist and, in its absence, chaos reigns. Even those who believe in disclosure don’t agree on details, such as how long a company should be given to respond. The lack of agreement means there’s no way to know when the next major flaw will be exposed, who it will come from, or how it will be reported.

It’s like strapping on a life vest as a ship sinks into frigid waters. Sure, the vest is a good idea, but it’s not enough to save you anymore.

Cyber security is a mess, and it’s a mess that’s taken its toll on each of us. While alarming, the new flaws in AMD processors — like Meltdown, Spectre, Heartbleed, and so many others before — will be soon be forgotten. They must be forgotten.

After all, what other choice do we have? Computers and smartphones have become mandatory for participation in modern society. Even those who don’t own them must use services that rely on them.

Every piece of software and hardware we use is, apparently, riddled with critical flaws. Even so, unless you decide to abandon society and build a cabin in the woods, you must use them.

Normally, I’d like this column to end on practical advice. Use strong passwords. Don’t click on links that promise free iPads. That sort of thing. Such advice remains true, but it feels like strapping on a life vest as a ship sinks in frigid arctic waters. Sure. The life vest is a good idea. You’re safer with it than without — but it’s not enough to save you anymore.

Editors' Recommendations

Matthew S. Smith
Matthew S. Smith is the former Lead Editor, Reviews at Digital Trends. He previously guided the Products Team, which dives…
AMD A-Series APUs, Athlon X4 CPUs are now available to the public
A-Series APUs

Although they were launched nearly a year ago for desktop manufacturers, AMD now provides its seventh-generation “Bristol Ridge” A-Series APUs (with graphics) and its Athlon X4 processors (no graphics) to mainstream markets such as Amazon and Newegg. The announcement was quietly slipped in with AMD’s Ryzen 3 launch on Thursday.

“The introduction of 7th Gen A-series, Athlon X4, and Ryzen 3 processors completes the stable, mature socket AM4 ecosystem, making it the only future-ready platform that scales all the way from entry-level CPUs all the way up to the high-end 8-core/16-thread Ryzen 7 1800X,” AMD said.

Read more
AMD’s new $10,000 graphics card has its own built-in SSDs
amd radeo pro duo ssg capsaicin rprossg

As much as gamers might be willing to spend on their PCs, their computers have nothing on the cost of high-end workstations, especially if those workstations use one of AMD's new Radeon Pro Solid State Graphics (SSG). The new $10,000 Radeon Pro Duo from AMD, comes equipped with its own pair of PCIExpress 3.0 M.2 slots for massively expanding its local storage.

Announced this week at the AMD Capsaicin event, which showcased many of the company's new VR and gaming developments, the new graphics card is aimed at professionals who need more than the 8GB of the standard Radeon Pro Duo, or even more than some of its largest professional graphics processors (GPU).

Read more
Google Hangouts now has its own Web page for your chatting convenience
Google Hangouts

Now that Google has given birth to its parent company, Alphabet, and subsequently split itself up into multiple divisions, it only makes sense that some of Google's most beloved features are finding a new home for itself as well. At least, that's what has happened with Google Hangouts, which now has its own Web page and is no longer hidden within Gmail and Google+. For those looking for an easy way to chat with their friends, you can now simply visit hangouts.google.com, and get hangin'.

Hangouts, which has long been a competitor of other video chatting services like Skype (and more recently, Facebook's Messenger), has undergone some serious reconstruction in the last few months. The iOS and Android versions of the service have both been redesigned and reworked, and now, its design appears more cohesive with the rest of the search engine's user interface. For the dedicated Hangouts user, who can use the communication platform for anything from chat to video messaging to phone calls, these improvements are long overdue, but seriously welcome.

Read more