Earlier quoted context omitted.
Intent matters, at least to me. This does not seem to be a case like VW's diesel-emissions shenanigans.
The problem still is: one of the units responsible for increasing the processor performance was not working correctly. So the increased performance of the processor was obtained by not working correctly. That qualifies as cheating - if not by intent but then by nature of the design. It remains to be investigated how much of the security implications of their design choices was or could have been known to Intel. The f…
Meltdown, aka “Dear Intel, you suck”
91–100 of 176 posts
Re: Meltdown, aka “Dear Intel, you suck”
#92Earlier quoted context omitted.
The most recent ARM chips (cortex A75) are vulnerable.
Didn't know that. The chipmaking business is insular and pretty incestuous, I wonder if the same engineers built both speculative execution units. I've got a friend in CPU design and he's only got about 50 companies he can work for in the world where he could do the same job he does now
I’ve written RTL that speculatively fetches data from memory in order to avoid bubbles in a pipeline. Not a CPU, but the concept is exactly the same.
If somebody had assigned me to a CPU project without guidance from a security architect and ask me to speculate reads, I’d probably have done the same as Intel.
The chance that the same guy did both CPUs is small. It’s just that it’s not an unreasonable way of doing thing if you’re not familiar with these kind of attack.
Re: Meltdown, aka “Dear Intel, you suck”
#93I don’t understand the Intel hate. It’s not like their engineers are dumb or lazy. This exploit is very hard to imagine before now. And it’s there because chip makers were trying to wring out more performance. It’s unfortunate if anythig.
The OpenBSD developers are mad that Intel didn't inform them, or any of the other BSDs. Only Microsoft and Linux developers where included in the information that was under embargo. I don't think they're upset that Intel made a mistake, not more so that most others anyway.
It's the technological version of insider trading
Re: Meltdown, aka “Dear Intel, you suck”
#94Earlier quoted context omitted.
> This exploit is very hard to imagine before now. It's really not. It's the sort of thing you wonder after first learning about out-of-order and speculative execution in a computer architecture class, but your professor assures you that implementors have been very careful to ensure any partial execution is properly flushed and rolled back. Then it turns out that, nope, no one's actually been keeping an eye on this a…
...but if it is "so obvious" - why has it taken ~20 years to discover it (publically)?
Life-safety work has no business in a public cloud.
Re: Meltdown, aka “Dear Intel, you suck”
#95Hi I'm a mostly average Linux user just now learning about these hardware vulnerabilities as I'm planning on building a new computer. What new processor should I buy that has the best chance of being safe when all this dust clears? I first posted this question on a thread about Intel ME. Have processors always been this tricky security-wise or are these low level exploits we're finding a recent phenomena?
Re: Meltdown, aka “Dear Intel, you suck”
#96Earlier quoted context omitted.
Well they did release their Coffee Lake generation chip after they already new about the exploit. Now i know it would take a lot for a major company to delay/cancel a release like that, but i think it could be argued that they were dishonest if they knew it would have a performance impact.
They would have had to delay it for a year or more.
If so, I hope the market punishes that decision mercilessly.
Re: Meltdown, aka “Dear Intel, you suck”
#97Earlier quoted context omitted.
Cleaner IPFS link: https://www.eternum.io/ipfs/QmQU1bCPsg7VY5puKqH6wZfAv1ZWBteK... By the way, here's a short script that will download a (full) page with wget, add it to IPFS (if you have a running daemon) and copy the Eternum link to clipboard: https://www.pastery.net/zxkzkc/
I love how that link just completely times out.
Re: Meltdown, aka “Dear Intel, you suck”
#98Earlier quoted context omitted.
From my perspective: I've been singing Intel's praises for the last decade as they regularly (for my own tests/usage) beat out AMD in performance, clock for clock if not dollar for dollar. With this recent news, I feel like part of the reason that Intel has been doing so well is that they have been _cheating_.
Clock speed has been an awful metric for 2 decades now (except for within a single CPU model series). All processors (including AMD/ARM) since the early 90's have been using instruction pipelining. It's a universal performance improvement, not Intel cheating.
Re: Meltdown, aka “Dear Intel, you suck”
#99I don’t understand the Intel hate. It’s not like their engineers are dumb or lazy. This exploit is very hard to imagine before now. And it’s there because chip makers were trying to wring out more performance. It’s unfortunate if anythig.
Re: Meltdown, aka “Dear Intel, you suck”
#100I mean I get it: large corporations (1) don't necessarily have my interests at heart; (2) are not able to perfectly execute (on extremely large and complicated) products and systems.
um. This is as radical as taking a stand that the sun sets in the west.
I like HN because of the promise that people think just a little bit before just typing something that strokes their feelz-good neurons. Yet, here we are on the front page with "In tel suxxx!" (and "Apple suxxx! in the htop thread, etc., etc. etc.)
sigh I guess it's inevitable.
People just don't like paying for intangible things, so the only way to pay for the internet is clickz/eyeballz. And OUTRGE! clickz/eyeballz are the cheapest and easiest.
I know, I know. There was a bug from vendor X that really irked/irks you and it feelz good to express your outrage.
I just wish there was just some corner of the internet where this wasn't the dominant trend and I had hoped it was here on HN. Well, at least reddit has extremely cute dog and kitten videos, and some chuckle-memes.