this post was submitted on 13 Jun 2026
478 points (99.6% liked)

Technology

85461 readers
3711 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] crazyduck@lemmy.zip 16 points 1 day ago

Except when he responsibly disclosed to AMD, they closed the ticket as "out of scope" without any further communication. He then made a blog post about it warning other users about the vulnerability since ostensibly, AMD didn't want to fix it. Only after that post had gone viral AMD suddenly came back saying that despite the ticket being closed as such, their internal security team was still analysing it and he should've somehow known that and that he violated the TOC of the bug bounty program (remember, after saying that the vulnerability was out of scope of the program). Additionally AMD then changes those terms a month after the initial ticket to suddenly say that even if the ticket is refused, you're still not allowed to talk about it. Then to top it off they take a month longer to fix it then is industry standard, don't disclose the fix to the researcher as is customary until a few days before release and only because he kept badgering them and as the cherry don't tell their users that the only way to securely fix this is by uninstalling and reinstalling. Everything about it is scummy behaviour all around.