Earlier quoted context omitted.
We know that people think that AMD is not affected by this permutation of the attack. Intel may know differently; I'd withhold sweeping claims.
You think Intel considers AMD vulnerable while AMD considers itself not vulnerable? That's quite an assumption to ask of us.
Intel Responds to Security Research Findings
91–100 of 245 posts
Re: Intel Responds to Security Research Findings
#92Earlier quoted context omitted.
We won't know until we know what the actual bug is. All we know is that people are writing patches for Intel chips, and what those patches do. It's very possible that other processors are affected by the same issue in some different way that doesn't require this set of patches to mitigate.
We know that AMD is not affected: https://lkml.org/lkml/2017/12/27/2
We do not know what the actual bug that prompted this activity is. Nobody has revealed that information. It is possible that the bug affects AMD also but does not require this patch.
Re: Intel Responds to Security Research Findings
#93Earlier quoted context omitted.
I mean, I am. I have a really nice laptop that I'd rather not have to replace.
If you have malicious applications running on your laptop you have bigger problems already...
Re: Intel Responds to Security Research Findings
#94It comes across as fairly defensive. Presumably the statement was hastily put together, but it's not really the tone you want to strike when you have a lot of worried customers wondering what is going on. > Intel believes its products are the most secure in the world and that, with the support of its partners, the current solutions to this issue provide the best possible security for its customers. A rather bizarre s…
It's odd that they named AMD and ARM, but did not name Apple and Microsoft, isn't it?
Re: Intel Responds to Security Research Findings
#95Lots of people being critical of this response. I think it's pretty good, and have been on the disclosing side of this equation many times. Admits responsibility and says their current course of action (working with key stakeholders). Addresses concerns of the workaround. Has a timeframe for future updates. Has a call to action for what you should be doing next. To those of you pointing out that this is PR, you're ri…
It's also manipulative, mentioning AMD and ARM for no other reason to make people think those also have the flaw.
Re: Intel Responds to Security Research Findings
#96> Contrary to some reports, any performance impacts are workload-dependent, and, for the average computer user, should not be significant and will be mitigated over time. Given the lack of any facts, evidence, or details in the press release, how is anyone supposed to take Intel seriously?
Devils advocate. Workload dependence... average user... not significant: A lot of users probably see "30%" and will assume the worst. There really isn't a lot of evidence of how much an average consumer will be affected. Pretty sure your average consumer isn't running pgbench all day. Hell, I'm willing to bargain 90% of servers (I really want to say more) are over-provisioned by 30% or more. Mitigated over time: Kern…
Re: Intel Responds to Security Research Findings
#97Earlier quoted context omitted.
We know that AMD is not affected: https://lkml.org/lkml/2017/12/27/2
We know that people think that AMD is not affected by this permutation of the attack. Intel may know differently; I'd withhold sweeping claims.
Sounds like AMD's chips are not affected by variants of this attack either. Sure, we should wait for the details to be published before making sweeping claims, but the details we have so far paint a reasonable picture of what the vulnerability involves. It is reasonable to assume that AMD's design decisions prevent this attack, while Intel's decisions enable it.
Re: Intel Responds to Security Research Findings
#98The reports are trickling in that Mossad has already exploited this security flaw to their advantage. Seems like the "flaw" may have been a backdoor designed by someone from their Haifa operations.
Seems like you have some bias here. Source?
Re: Intel Responds to Security Research Findings
#99Earlier quoted context omitted.
Not defending Intel here, but devils advocate... You will find many clients asking how to disable, for example, the Linux patch. Linux is releasing with a flag to disable it, so there is some merit. Why would you want that? There are a lot of times you trust everything running on your box and don't need to take the perf hit. Intel (and possibly other archs/families) found a perf win that ends up having security impli…
Intel is certainly entitled to make and promulgate an objective assessment of the impact of the problem, but a problem is still a problem even if it doesn't affect everyone.
The issue is embargoed, but that's, as usual, not keeping everyone from speculating. That's fine too, but also realize the layman (even people in this thread) is getting pummeled with ideas like "my new laptop is going to be 30% slower tomorrow; WTF!!!"