The RCE that AMD wouldn't fix(mrbruh.com)
280 points by MrBruh 19 hours ago | 117 comments
tl;dr: A researcher found that AMD's AutoUpdate tool downloads executables over HTTP without signature verification, enabling trivial MITM RCE attacks. AMD initially dismissed it as out-of-scope for their bounty program, then asked him to take down his blog and demanded an embargo far exceeding the 90-day industry standard—ultimately taking 124 days to fix by changing HTTP to HTTPS. The patch claims signature verification, but it's actually just a CRC-32 check, and the updater was already broken anyway due to an unrelated unhandled redirect.
HN Discussion:
  • The CRC-32 'signature verification' fix is laughably inadequate and HTTPS alone isn't enough
  • AMD's software incompetence is a long-standing, broader pattern beyond this incident
  • Bug bounty programs commonly weaponize ToS to suppress disclosure, full disclosure is preferable
  • MITM should obviously be in-scope; assume the internet is hostile by default
  • AMD acknowledged the vulnerability but reasonably excluded it from bounty scope due to internal incentives