Live data from Hacker News

“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

marc.info

21–30 of 130 posts

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#21
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

(playing devil's advocate here, to be clear) What leads you to believe that Intel has any reason to think that there's an issue that needs changed? Or that "the community" knows anything about their business processes or what Intel should do? They have their highly-paid C-levels to figure that out. From their perspective, there's no problem. Nothing needs fixin'. You'll keep buying their CPUs, anyways -- you don't re…

Basically buying new Intel processor to replace old will yield 5-60% performance in I/O-heavy workloads even without any other changes but fixed processor bug, unless you're ready to tweak with your OS settings and fine with potential vulnerability. With proper marketing they can make huge profits from this situation. Sure, you can buy AMD, but Intel is still faster for many benchmarks. Given that they knew about bug for 7 months, I think that soon new processors will be without Meltdown bug.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#22
post #4
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…

>They can a handle a bit of criticism from a bunch of nerds on HN.

What a reductive and shortsighted evaluation of the situation.

Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention security minded users) that require technology that is both resistant to meltdown and not underperforming hardware.

It's silly to act like this is a storm in a teacup because the HN community is up in arms over it. Monopolies fall, and the loss of trust and key clients tends to precipitate that fall.

>But if it needs help drafting a better PR release, someone is welcome to point them to HN's comments section.

Their PR was shocking, but on the order of things people are upset about over this incident, this is literally at the bottom.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#23
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

They had $4.5 billion in profit last quarter. If they want help, they can pay for it.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#24
The linked intel erata pdf file is 404'ing, but I think this [0] matches if you are curious about this line:

> Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us.

[0]: http://download.intel.com/design/processor/specupdt/313279.p...

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#25
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

If it's possible to get an eventual legal judgement against them, perhaps instead of paying x-billion dollars in fines, maybe they should be forced to make their future work open source.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#27

At least one of the recent exploits needs to be mitigated at the OS level (I haven't looked at the details carefully, but I know Microsoft and Linux are working on it). Is OpenBSD affected and if so, what are they doing to mitigate it?

Affected and probably doing what everybody is doing for mitigation.

> probably doing what everybody is doing for mitigation

Is there any discussion? I thought OpenBSD development mostly took place on public mailing lists ?

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#28

Wow. This is bad for Intel. Industry experts have been expressing concerns for this for ten years. Does this open Intel up to possible repercussions?

> Industry experts have been expressing concerns for this for ten years.

AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#29

This image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!

Is it just me or do AE4 and AE11 have the same description (REP MOVS crossing pages of different types) yet completely different classification/impact?

IIRC this behaviour is now documented in the official manuals as "by design" since it was like that since the P3.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#30
post #24

The linked intel erata pdf file is 404'ing, but I think this [0] matches if you are curious about this line: > Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us. [0]: http://download.intel.com/design/processor/specupdt/313279.p...

ugh, I checked some of them, and most of them suggest accessing protected memory.

I believe that Intel didn't believe that these bugs suggest a fundamental issue that can be exploited, until Google Project Zero created a working exploit.

Post reply on HN