Live data from Hacker News

“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

marc.info

31–40 of 130 posts

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#31
post #22
post #4

Earlier quoted context omitted.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…

>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention…

> They can a handle a bit of criticism from a bunch of nerds on HN.

It was a tongue-in-cheek response to OPs statement that we should feel bad for Intel and offer it help. I suggested that it needs help drafting a better PR release that's a bit more honest and straightforward.

> Can they handle the loss of faith from big companies?

With a $200B capitalization they certainly can.

> Seems to me that AMD et al have now got the perfect opportunity to erode

Agreed. The next step is to see if any of the large cloud providers or PC manufacturers will announce they are buying AMD CPUs. I hope because I'd like to be able to buy cheaper CPUs and have more competitors in the market. But realistically I kind of doubt it. At the end of the day INTC's stock hasn't moved that much. The performance hit as reported by Google didn't seem to as big.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#32
post #22
post #4

Earlier quoted context omitted.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…

>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention…

PR is always shocking.

Let's wait to see how much performance is lost and what vulnerabilities get used in the wild.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#34
There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count).

EDIT: oh, and using the NoScript browser add-on :)

To all the downvoters: please prove me wrong by replying ;)

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#35

There's nothing prescient about saying that computer system X or Y can be exploited in ways yet to be discovered. The entire Internet is wide open, the holes just aren't known yet.

You miss the point. Theo wasn't just hand waving, he had identified specific issues that he believed would eventually get exploited.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#36

There's nothing prescient about saying that computer system X or Y can be exploited in ways yet to be discovered. The entire Internet is wide open, the holes just aren't known yet.

care to enlighten us about this statement, wise one?

> For instance, AI90 is exploitable on some operating systems (but not OpenBSD running default binaries).

if you know how the processor and OS behaves at a low level, and read specific hardware errata which you know will cause problems that logically cannot be worked around, developing a proof of concept (aka 'discovering') is simply a waste of time and effort..

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#37

Wow. This is bad for Intel. Industry experts have been expressing concerns for this for ten years. Does this open Intel up to possible repercussions?

> Industry experts have been expressing concerns for this for ten years. AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.

> AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular.

Really?

How do you explain the following:

> These processors are buggy as hell, and some of these bugs don't just cause development/debugging problems, but will ASSUREDLY be exploitable from userland code.

> Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us.

> AI90 is exploitable on some operating systems (but not OpenBSD running default binaries).

Plus huge development effort in stack/address randomization, W^X pages, dynamic kernel and c library relinking, etc as simply 'concern about intel in general' but not any details 'in particular'?

Even if the stated position is not true, it would be logically inconsistent to assume someone whose operating system project focuses on 'security and correctness' to simply be making general statements and not being concerned with actual low-level details..

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#38
post #22
post #4

Earlier quoted context omitted.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…

>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention…

AMD’s x86/x86-64 Cross licensing agreement terminates if they ever have more than X (I think 30% or 50%) of the desktop and server market share, so I don’t think so. The agreement purposefully gimps AMD as a minority player.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#40
post #31
post #22

Earlier quoted context omitted.

>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention…

> They can a handle a bit of criticism from a bunch of nerds on HN. It was a tongue-in-cheek response to OPs statement that we should feel bad for Intel and offer it help. I suggested that it needs help drafting a better PR release that's a bit more honest and straightforward. > Can they handle the loss of faith from big companies? With a $200B capitalization they certainly can. > Seems to me that AMD et al have now…

> At the end of the day INTC's stock hasn't moved that much.

nor should it.. huge stock (so less speculators), many products besides x86 PC processors, and their reaction/fix to this & subsequent impact to actual earnings hasn't shaken out..

not pro or against intel. but mentioning this as concerns market stuffs.

Post reply on HN