Live data from Hacker News

“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

marc.info

41–50 of 130 posts

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#41
post #38
post #22

Earlier quoted context omitted.

>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention…

AMD’s x86/x86-64 Cross licensing agreement terminates if they ever have more than X (I think 30% or 50%) of the desktop and server market share, so I don’t think so. The agreement purposefully gimps AMD as a minority player.

> AMD’s x86/x86-64 Cross licensing agreement terminates if they ever have more than X (I think 30% or 50%)

Wow I'm surprised this is even legal because it sounds like an implemented monopoly.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#42
post #4
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…

The Register did a great analysis of turning the Intel Press release into English.

"We translated Intel's attempt to spin its way out of CPU security bug PR nightmare as Linus Torvalds lets rip on Chipzilla"

https://www.theregister.co.uk/2018/01/04/intel_meltdown_spec...

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#44
post #41
post #38

Earlier quoted context omitted.

AMD’s x86/x86-64 Cross licensing agreement terminates if they ever have more than X (I think 30% or 50%) of the desktop and server market share, so I don’t think so. The agreement purposefully gimps AMD as a minority player.

> AMD’s x86/x86-64 Cross licensing agreement terminates if they ever have more than X (I think 30% or 50%) Wow I'm surprised this is even legal because it sounds like an implemented monopoly.

Well if it means that AMD couldn't ship any x86 processors and Intel couldn't ship x86-64 (i.e. AMD64) processors, that effectively means neither of them could ship any modern x86 processors at all, so that's effectively mutually-assured destruction. If that were in any danger of happening I'd bet dollars to donuts it'd be renegotiated immediately since they both stand to lose everything.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#47
post #37

Earlier quoted context omitted.

> Industry experts have been expressing concerns for this for ten years. AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.

> AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. Really? How do you explain the following: > These processors are buggy as hell, and some of these bugs don't just cause development/debugging problems, but will ASSUREDLY be exploitable from userland code. > Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us. > AI90 is exploitable on…

What forapurpose said: > but not the recent exploits in particular

What you said: > but not any details 'in particular'?

Looking at the list of items Theo gave, most of them were fixed previously, and the others, at least to my largely uneducated eye, do not appear to be related to this specific issue.

Unless I am mistaken (and that's certainly possible!) it was not at all related to Spectre/Meltdown

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#49
post #22
post #4

Earlier quoted context omitted.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…

>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention…

Their shockingly bad PR and general response are directly tied to the loss of trust. Sure, the downfall of a monopoly is economically disruptive but also creates opportunities for progress.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#50
post #46

Earlier quoted context omitted.

That and off by one errors ;)

Concurrency You forgot 2) Cache invalidation and 3)

Haha, you are correct, but there are some other hard problems that I now remember after some quick googling since i forgot all the related jokes :)

There are only two hard problems in distributed systems: 2. Exactly-once delivery 1. Guaranteed order of messages 2. Exactly-once delivery

There's two hard problems in computer science: we only have one joke and it's not funny.

Source: https://martinfowler.com/bliki/TwoHardThings.html

Post reply on HN