Live data from Hacker News

Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

bloomberg.com

71–80 of 567 posts

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#71
post #43
post #19

This is a clusterf /big deal. Beyond the security implications, it means that all companies paying for computing resources will have to pay roughly 30% more overnight on cloud expenses for the same amount of CPU, assuming that they can just scale up their infrastructure. I know that bugs happen and that there was nothing intentional on this one, but at times like this is hard to held at bay the temptation of claiming…

> I know that bugs happen This isn’t an excuse for Intel consistently having terrible verification practices and shipping horrendous hardware bugs. From 2015: https://danluu.com/cpu-bugs/ There have been more since then. I’ve talked to multiple people who work in intel’s testing division and think “verification” means “unit tests”. The complexity of their CPUs has far surpassed what they know how to manage.

Sounds like Facebook and Youtube, too.

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#72
post #52

Can someone help me understand why this is such a big deal? This doesn’t seem to be a flaw in the sense of the Pentium FDIV bug where the processor returned incorrect data. It doesn’t even seem to be a bug at all, but a side channel attack that would be almost expected in a processor with speculative execution unless special measures were taken to prevent it. And it doesn’t seem like it can be used for privilege esca…

There is this thing called "return oriented programming". You write your program as a series of addresses that are smashed onto the stack through some other type of vulnerability. When the current function returns, it returns to an address of your choosing. That address points to the tail end of some known existing function, such as in the C library and other libraries. When the tail end of that function returns, it executes your next "instruction" which is merely the next return address on the stack.

The first "instruction" of your program is the last address on the stack, in the list of addresses you pushed to the stack.

You are executing code, but you did not inject any executable code, you did not need to modify any existing code pages (which are probably read only), you did not need to attempt to execute code out of a data page (which is probably marked non executable).

Address Space Layout Randomization is a way to prevent the "return oriented programming" attack. When a process is launched, the address space is randomly laid out so that the attacker cannot know which address in memory the std C lib printf function will be located at -- in this process.

Now let's think about the kernel. If you could know all of the addresses of important kernel routines, you could potentially execute a "return oriented programming" attack against the kernel with kernel privileges. Without modifying or injecting any kernel level code. These hardware vulnerabilities allow user space code to deduce information about kernel space addresses.

Now that's a lot of hoops to jump through in order to execute an attack. But there are people prepared to expend this and even more effort in order to do so. Well funded and well staffed adversaries who would stop at nothing in order to access more and better pr0n collections.

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#73
post #56

"Intel has a bug that lets some software gain access to parts of a computer’s memory that are set aside to protect things like passwords." Seems like very little got through to the media about the details regarding this flaws effects and costly workaround.

This reddit thread has more information on the bug https://www.reddit.com/r/sysadmin/comments/7nl8r0/intel_bug_...

That Reddit thread is repeating back information from previous hacker news threads.

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#74
post #68

The bottom of https://danluu.com/cpu-bugs/ suggests that AMD isn't any better, so this is likely just short term.

They don't have to be better to benefit from purchasers wanting to diversify their plant across two rather than one CPU vendors.

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#75
post #48

Earlier quoted context omitted.

Seems debatable. From what I recall, at least some news about this issue was already public before he sold his shares. And what would be illegal would be trading based on information that isn't public. OTOH, since details are still dribbling out, you could possibly argue that the Intel CEO had more complete information than the public. The sell could also have been scheduled in advance, which would - AFAIK - not viol…

Unless the advance scheduling is completely binding, I don't see why that should sidestep insider trading. What's to stop these guys from always having a cascading series of sells and buys 6 mo. in advance, and just cancelling them?

What is to "stop these guys" is the legal parties and officials involved have brains that they can use. The engineer idea of "mwa ha ha, I found a bug, I can walk" is rarely true in practice (n.b.: having quite a lot of money is a different kind of exception).

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#77
post #69
post #43

Earlier quoted context omitted.

> I know that bugs happen This isn’t an excuse for Intel consistently having terrible verification practices and shipping horrendous hardware bugs. From 2015: https://danluu.com/cpu-bugs/ There have been more since then. I’ve talked to multiple people who work in intel’s testing division and think “verification” means “unit tests”. The complexity of their CPUs has far surpassed what they know how to manage.

This is typically what happens when you go for a long time without real competition. You get way too comfortable and bad habits start to pile up.

Isn't why this problem even exits the exact opposite? Intel was losing on the mobile market and changed internal testing to iterate faster by cutting corners.

Found a quote:

"We need to move faster. Validation at Intel is taking much longer than it does for our competition. We need to do whatever we can to reduce those times… we can’t live forever in the shadow of the early 90’s FDIV bug, we need to move on. Our competition is moving much faster than we are".

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#78
post #20

Didn’t the Intel CEO just sell half of his shares/options? If he knew about these issues isn’t that illegal?

I saw that rumor spreading last night, but have yet to see any trustworthy reporting on any such action. Edit: Here's trustworthy reporting on that action that also predates this announcement: https://www.fool.com/investing/2017/12/19/intels-ceo-just-so...

> that also predates this announcement

Apparently, Microsoft has been releasing patches for NT since November, so it isn't exactly predating the bug.

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#79
I'm worried about the performance impact on low end intel chips like Atom/Celeron found in Chromebooks.30% hit will make computing on those platforms miserable.

Talking about chromeOS, is there any speculation about the impact of bug? Does it's hardened sand-boxing techniques put it in a better position even if KASLR is compromised?

Re: Intel Confronts Potential ‘PR Nightmare’ With Reported Chip Flaw

#80

Earlier quoted context omitted.

> It's trying to stare into some crystal ball guessing at the cause of market fluctuations; but there's no real evidence they're right. Welcome to the world of business reporting.

I think it's pretty clear in this case. Plenty of people here in hn-land were talking about Intel/AMD short/long positions starting in the afternoon yesterday and word has gotten around.

Talk is cheap; investing perhaps less so. The asserted "soaring" stock price simply hasn't happened. The 7% rise they name as "soaring" is not a soar for a stock this volatile: https://www.bloomberg.com/quote/AMD:US - just look at the graph over the past year; value changes in excess of 50% happened several times.

To be clear; I'm not saying this increase won't stick, just that bloomberg is pretending they're reading this from the numbers, not merely expecting it to occur. It'd be fine to say you might expect the stock to trend higher. But pretending you can look at that noisy line and say the current 7% increase is statistically significantly higher in a humanly relevant way is just hogwash.

Obviously you might expect the stock to soar. It may well happen. It just isn't visible in the data they present; the article is simply click bait (or worse, market manipulation).

Post reply on HN