• pulsewidth@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    $10k is nothing to AMD. The middle-management bean counters making these decisions are actively harming their company’s (and user’s security.

    • bamboo@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      The flaw of not using HTTPS for the downloads is so basic it’s shocking they didn’t have internal tooling to raise this before it was shipped. I’m not familiar with AMD’s bug bounty policy but they should have at least paid $1337 to the researcher for raising this to them.