Live data from Hacker News

“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

marc.info

121–130 of 130 posts

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#121

Earlier quoted context omitted.

> Industry experts have been expressing concerns for this for ten years. AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.

They were more than general points. Please don't poo-poo this as some sort of horoscope doom and gloom post. He specifically pointed out the the issues addressed in the recent disclosures: > It is not just buggy, but Intel has gone further and defined "new ways to handle page tables" (see page 58). The MMU, page tables, and TLB are all directly related.

> Please don't poo-poo this as some sort of horoscope doom and gloom post

That wasn't my intent at all. de Raadt makes good, generally applicable points.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#122

Earlier quoted context omitted.

> probably doing what everybody is doing for mitigation Is there any discussion? I thought OpenBSD development mostly took place on public mailing lists ?

Some issues tend to attract a lot of lookie loos. The patch probably won't be improved by a dozen replies about the incompetence of intel.

[deleted]

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#123

Earlier quoted context omitted.

> probably doing what everybody is doing for mitigation Is there any discussion? I thought OpenBSD development mostly took place on public mailing lists ?

Some issues tend to attract a lot of lookie loos. The patch probably won't be improved by a dozen replies about the incompetence of intel.

I understand their need and priority, but sometimes those discussions are a great way to learn about the vulnerability - open development teaches others.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#124
post #30
post #24

The linked intel erata pdf file is 404'ing, but I think this [0] matches if you are curious about this line: > Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us. [0]: http://download.intel.com/design/processor/specupdt/313279.p...

ugh, I checked some of them, and most of them suggest accessing protected memory. I believe that Intel didn't believe that these bugs suggest a fundamental issue that can be exploited, until Google Project Zero created a working exploit.

[deleted]

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#125
post #38
post #22

Earlier quoted context omitted.

>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention…

AMD’s x86/x86-64 Cross licensing agreement terminates if they ever have more than X (I think 30% or 50%) of the desktop and server market share, so I don’t think so. The agreement purposefully gimps AMD as a minority player.

This is strange, I’d never heard of this agreement. As I understand it, Intel x86-64 was actually based on AMD’s amd64 design originally. So in reality they are still two separate architectures in a sense?

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#126

Earlier quoted context omitted.

Some issues tend to attract a lot of lookie loos. The patch probably won't be improved by a dozen replies about the incompetence of intel.

I understand their need and priority, but sometimes those discussions are a great way to learn about the vulnerability - open development teaches others.

I don't disagree. I prefer more open development and try to encourage it, but everyone has their own preferences for what to share.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#127

Earlier quoted context omitted.

You're (and most likely all downvoters) completely missing the point. I never said that opensource software is not affected, I said "not being affected as a user". Because opensource software, being peer-reviewed, will never try to exploit a CPU bug. Opensource software is, by default, non-malicious.

Being open source and peer-reviewed doesn't mean software won't have bugs, exploits, or that backdoors can't be hidden in it. 'Peer-reviewed' sounds good on paper, but people can still miss things, be lazy, or not understand the code they are reviewing (but it works, so accept merge!). It's hardly the silver bullet to this problem. As for your original post - moving to FOSS only is not viable for a lot of people. Lin…

> moving to FOSS only is not viable for a lot of people

I never advocated for people moving to FOSS. I just said it's a way to not be affected by these bugs, end of story. If the disadvantages of people moving to FOSS don't outweight the benefits, fine for them.

> You can't seriously expect an average user to manually whitelist javascript in the sites they browse.

Fair enough, that's why I only added "NoScript add-on" as an after thought.

> Until this changes there will be no 'year of the Linux Desktop'

Good to know your PoV on this.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#128

Earlier quoted context omitted.

same, and don't bother reading too much, the best bugs came after ... incredible how I (we) ran on buggy hardware for so long. We should fund a tiny group for sane cpu design.

Order your Raptor Engineering Talos™ II now! Improved with PCI Express 4.0, CAPI 2.0, DDR4 RAM, & POWER9 CPU. https://raptorcs.com/TALOSII/

but power is not immune from this right ?

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#129
post #85
post #78

I know I will sound like a conspiracy theorist, but can those bugs be intentional? I mean if you are a security agency, would it be possible to push for the introduction of such bugs?

Occam's Razor suggests to me that intelligence agencies have not had to push for processor bugs, on the grounds that A: we can adequately explain the initial existence of these bugs by normal engineering, marketing, and management considerations such as almost everyone here has experienced personally and B: the field of the bugs that come from my first point is so ripe that the intelligence agencies are better served…

Who's Occam, and why is he an authority on guessing the truth again?

Yes, I'm kidding about the first part.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#130

Earlier quoted context omitted.

Order your Raptor Engineering Talos™ II now! Improved with PCI Express 4.0, CAPI 2.0, DDR4 RAM, & POWER9 CPU. https://raptorcs.com/TALOSII/

but power is not immune from this right ?

According to Raptor Engineering on Jan 5: "#POWER8 and prerelease variants of #POWER9 vulnerable to #Meltdown (CVE-2017-5754) and #Spectre (CVE-2017-5753 / CVE-2017-5715). #POWER9 is being patched and will not be vulnerable at ship, and there will be no performance loss versus current #POWER9 samples. Patches coming soon."[0]

[0] https://twitter.com/RaptorCompSys/status/949368929507520517

Post reply on HN