Earlier quoted context omitted.
You miss the point. Theo wasn't just hand waving, he had identified specific issues that he believed would eventually get exploited.
" he had identified specific issues that he believed would eventually get exploited " But those aren't the issues that were exploited. His post has absolutely nothing to do with the current issues. It's just uninformed dogpiling (the ignorance of the crowd). All chips have errata. This post is not particularly informative or relevant to anything.
“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
91–100 of 130 posts
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#92I know I will sound like a conspiracy theorist, but can those bugs be intentional? I mean if you are a security agency, would it be possible to push for the introduction of such bugs?
What is likely is that security agencies with their larger staffs and budgets do discover many of them before the private sector. It's certainly plausible that the NSA knew about this new class of attacks before we did.
BTW -- forget about CPUs. My biggest concern is with the chips that get less security attention: GPUs, network chips, USB controllers, etc. Those are likely just as bug-ridden or more.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#93Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#94I know I will sound like a conspiracy theorist, but can those bugs be intentional? I mean if you are a security agency, would it be possible to push for the introduction of such bugs?
Occam's Razor suggests to me that intelligence agencies have not had to push for processor bugs, on the grounds that A: we can adequately explain the initial existence of these bugs by normal engineering, marketing, and management considerations such as almost everyone here has experienced personally and B: the field of the bugs that come from my first point is so ripe that the intelligence agencies are better served…
Since neither the threat nor the reality of PR disasters has ever given the NSA pause before, occam's razor strongly suggests this theory of yours is wrong.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#95I know I will sound like a conspiracy theorist, but can those bugs be intentional? I mean if you are a security agency, would it be possible to push for the introduction of such bugs?
Does the NSA use Intel chips? If so, it would seem unlikely that they made their own compute infrastructure insecure. Their mission isn't to make everything less secure, it's to make the other team's stuff less secure (where "other team" includes the citizens of the US apparently). Furthermore, given the number of bugs in just about every piece of software (including kernels), I don't think these bugs are even an ano…
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#96Earlier quoted context omitted.
Occam's Razor suggests to me that intelligence agencies have not had to push for processor bugs, on the grounds that A: we can adequately explain the initial existence of these bugs by normal engineering, marketing, and management considerations such as almost everyone here has experienced personally and B: the field of the bugs that come from my first point is so ripe that the intelligence agencies are better served…
>there is zero risk of it ever being revealed that they deliberately inserted bugs into the CPU, which would be a PR disaster Since neither the threat nor the reality of PR disasters has ever given the NSA pause before, occam's razor strongly suggests this theory of yours is wrong.
I would also disagree that your assessment is correct anyhow; they are insensitive to certain kinds of bad PR, but not generally immune to it, nor do they act generally immune to it. The people in charge of funding the intelligence community may not come after them for getting caught putting backdoors in things; indeed, this may even prove to the people controlling the purse that they are doing their job. But they are certainly sensitive to ensuring that the people controlling the purse do not come off looking bad, and as a part of that, sensitive to not getting caught conducting open, unambiguous acts of war against every nation in the world. We all "know" that they do, everybody else "knows" that they do, and everybody also "knows" that you shouldn't trust Chinese-manufactured electronics either for the same reason, but it's still not openly known. The distinction between open secrets and openly-known facts may greatly confuse Spock and he may shake his head about how illogical it is for everyone to know a thing and for everybody to know everybody else knows but still act as if nobody knows, but is an integral element of understanding human politics, in which appearances matter a lot.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#97Earlier quoted context omitted.
Occam's Razor suggests to me that intelligence agencies have not had to push for processor bugs, on the grounds that A: we can adequately explain the initial existence of these bugs by normal engineering, marketing, and management considerations such as almost everyone here has experienced personally and B: the field of the bugs that come from my first point is so ripe that the intelligence agencies are better served…
>there is zero risk of it ever being revealed that they deliberately inserted bugs into the CPU, which would be a PR disaster Since neither the threat nor the reality of PR disasters has ever given the NSA pause before, occam's razor strongly suggests this theory of yours is wrong.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#98This image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!
same, and don't bother reading too much, the best bugs came after ... incredible how I (we) ran on buggy hardware for so long. We should fund a tiny group for sane cpu design.
It's happened, again and again. The ARM CPUs powering your phones are a good example. Maybe with more of a market, POWER9 prices might come down.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#99This image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!
same, and don't bother reading too much, the best bugs came after ... incredible how I (we) ran on buggy hardware for so long. We should fund a tiny group for sane cpu design.
Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
#100Earlier quoted context omitted.
same, and don't bother reading too much, the best bugs came after ... incredible how I (we) ran on buggy hardware for so long. We should fund a tiny group for sane cpu design.
> We should fund a tiny group for sane cpu design. It's happened, again and again. The ARM CPUs powering your phones are a good example. Maybe with more of a market, POWER9 prices might come down.
They are saner but the problem is still here