Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
IMO the first step would be disclosing all their tricks they implement outside of the specs they give. If researchers had adequate documentation of all the side effects that these tricks introduce then it could be properly audited.
“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
11–20 of 130 posts
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#12At least one of the recent exploits needs to be mitigated at the OS level (I haven't looked at the details carefully, but I know Microsoft and Linux are working on it). Is OpenBSD affected and if so, what are they doing to mitigate it?
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#13I'm just surprised that the URL is still valid after 12 years!
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#14Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#15Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
What leads you to believe that Intel has any reason to think that there's an issue that needs changed? Or that "the community" knows anything about their business processes or what Intel should do? They have their highly-paid C-levels to figure that out.
From their perspective, there's no problem. Nothing needs fixin'. You'll keep buying their CPUs, anyways -- you don't really have much of a choice, do you? [0]
Just go install those updates from your vendor(s) and go about your business, you'll be fine. No big deal, nothing to worry about. Carry on. Just like you did with that recent little ME/AMT issue. There'll be another issue to deal with in a few days and everyone will forget all about this one.
[0]: Oh, you're gonna replace all your infrastructure with AMD's CPUs, huh? Yeah, sure you are. They're no different.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#16>As I said before, hiding in this list are 20-30 bugs that cannot be worked around by operating systems, and will be potentially exploitable. I would bet a lot of money that at least 2-3 of them are.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#17Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#18Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#19Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…
* http://www.theregister.co.uk/2018/01/04/intel_meltdown_spect... https://news.ycombinator.com/item?id=16064545 (https://newsroom.intel.com/news/intel-responds-to-security-r...)
* https://news.ycombinator.com/item?id=16072368 (https://newsroom.intel.com/news-releases/intel-issues-update...)
* https://news.ycombinator.com/item?id=16067245 (https://www.amd.com/en/corporate/speculative-execution)
* https://news.ycombinator.com/item?id=16068118 (https://developer.arm.com/support/security-update)
* https://news.ycombinator.com/item?id=16072912 (http://blog.dustinkirkland.com/2018/01/ubuntu-updates-for-me...)
* https://news.ycombinator.com/item?id=16071769 (https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAn...)
* No headline, although mentioned at https://news.ycombinator.com/item?id=16074531 and elsewhere (https://www.freebsd.org/news/newsflash.html#event20180104:01)
* https://news.ycombinator.com/item?id=16076660 (https://support.microsoft.com/en-gb/help/4072699/important-i... https://support.microsoft.com/en-gb/help/4072698/windows-ser... )
* https://news.ycombinator.com/item?id=16075348 (https://support.apple.com/en-gb/HT208394)
* https://news.ycombinator.com/item?id=16076175 (https://lists.debian.org/debian-security-announce/2018/msg00...)
* https://news.ycombinator.com/item?id=16076328 (https://lists.opensuse.org/opensuse-updates/2018-01/msg00000...)