Ok, so these "AMD flaws" are nowhere near anything like Meltdown or Spectre.
According to their "whitepaper", it lets you pwn your PSP and chipset if you already have root access on the main CPU. In the worst case, it's like the Intel ME BUP bug from december.
It's useful for researchers, coreboot porting, breaking DRM, etc. But it's no use for a remote (or even unprivileged local) attacker.
Their website makes it look way more dangerous than it is.
Then there's a lot of fishy stuff, like
- too much effort went into the website's design
- the website has lots of infographics and not-very-specific text, repeating the same things over and over again
- the whitepaper doesn't look like a whitepaper, and seems to be written with non-technical people in mind, especially the first few pages
- they have a huge legal disclaimer that says they may have financial interest in the value of AMD shares
- cts-labs.com exists for less than 1 year
@Wolf480pl also they only gave AMD 24 hours notice. 'responsible' disclosure my ass.
And I'm not picking on researchers for disclosing the flaws. I'm picking on them for making it look like a CPU flaw, like-Meltdown-except-worse. And telling people that their network is in danger because of it.
Also, the researchers didn't disclose any technical details, ust a bunch of noise.
It just looks like a hoax or an attempt to harm AMD by spreading FUD.
The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!