Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
(playing devil's advocate here, to be clear) What leads you to believe that Intel has any reason to think that there's an issue that needs changed? Or that "the community" knows anything about their business processes or what Intel should do? They have their highly-paid C-levels to figure that out. From their perspective, there's no problem. Nothing needs fixin'. You'll keep buying their CPUs, anyways -- you don't re…
“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
21–30 of 130 posts
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#22Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…
What a reductive and shortsighted evaluation of the situation.
Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention security minded users) that require technology that is both resistant to meltdown and not underperforming hardware.
It's silly to act like this is a storm in a teacup because the HN community is up in arms over it. Monopolies fall, and the loss of trust and key clients tends to precipitate that fall.
>But if it needs help drafting a better PR release, someone is welcome to point them to HN's comments section.
Their PR was shocking, but on the order of things people are upset about over this incident, this is literally at the bottom.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#23Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#24> Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us.
[0]: http://download.intel.com/design/processor/specupdt/313279.p...
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#25Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#26If only he had come up with a catchy name and a logo, we would have listened.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#27At least one of the recent exploits needs to be mitigated at the OS level (I haven't looked at the details carefully, but I know Microsoft and Linux are working on it). Is OpenBSD affected and if so, what are they doing to mitigate it?
Affected and probably doing what everybody is doing for mitigation.
Is there any discussion? I thought OpenBSD development mostly took place on public mailing lists ?
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#28Wow. This is bad for Intel. Industry experts have been expressing concerns for this for ten years. Does this open Intel up to possible repercussions?
AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#29This image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!
IIRC this behaviour is now documented in the official manuals as "by design" since it was like that since the P3.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#30The linked intel erata pdf file is 404'ing, but I think this [0] matches if you are curious about this line: > Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us. [0]: http://download.intel.com/design/processor/specupdt/313279.p...
I believe that Intel didn't believe that these bugs suggest a fundamental issue that can be exploited, until Google Project Zero created a working exploit.