Live data from Hacker News

Meltdown, aka “Dear Intel, you suck”

marc.info

111–120 of 176 posts

Re: Meltdown, aka “Dear Intel, you suck”

#111
post #95

Hi I'm a mostly average Linux user just now learning about these hardware vulnerabilities as I'm planning on building a new computer. What new processor should I buy that has the best chance of being safe when all this dust clears? I first posted this question on a thread about Intel ME. Have processors always been this tricky security-wise or are these low level exploits we're finding a recent phenomena?

You could go with AMD which is seemingly immune to Meltdown, but apparently someone already found a security flaw with their PSP (aka their own Intel ME).

If you need security and it doesn't need to be fast, use a raspberry pi.

No ME, no PSP, no meltdown, and no spectre.

Re: Meltdown, aka “Dear Intel, you suck”

#112
post #103
post #100

Is it the right time to call out the fundamental wrongness of Intel(/Apple/Microsoft/etc) outrage narratives? I mean I get it: large corporations (1) don't necessarily have my interests at heart; (2) are not able to perfectly execute (on extremely large and complicated) products and systems. um. This is as radical as taking a stand that the sun sets in the west. I like HN because of the promise that people think just…

>I just wish there was just some corner of the internet where this wasn't the dominant trend and I had hoped it was here on HN You're not going to find that, because taking the path of least intellectual and emotional resistance is just human nature. There is a positive feedback loop with outrage narratives that feeds people's ego and sense of in-group superiority, where one either feels empowered by agreement, or fe…

> "...taking the path of least intellectual and emotional resistance is fundamental to human nature. There is a positive feedback loop..."

I agree that both of those appear to be fundamental elements of human psychology. Fortunately, we're also have the ability to counteract this, either individually via self-reflection, or more easily, through feedback from others. We can be aware of these tendencies and work to counteract them. If the community has a common goal to do so, to encourage the "better angels of our nature" as it were, we can do better together than we may find it easy to do on our own. And that doesn't have to be a pretense. It can be an explicit, earnest value.

Re: Meltdown, aka “Dear Intel, you suck”

#113

Hi I'm a mostly average Linux user just now learning about these hardware vulnerabilities as I'm planning on building a new computer. What new processor should I buy that has the best chance of being safe when all this dust clears? I first posted this question on a thread about Intel ME. Have processors always been this tricky security-wise or are these low level exploits we're finding a recent phenomena?

My opinion is that it doesn't matter which processor you buy because you will have the same important dependencies irregardless. Intel or AMD, you will depend on the expertise of the operating system designers, the chip manufacturer, and the trustworthiness of the code you run. The presence of disclosed vulnerabilities in Intel chips does not reduce the probability of undisclosed or undiscovered vulnerabilities in AMD chips. The number of possible vulnerabilities in AMD chips is a very large number. The number of possible vulnerabilities in Intel chips is a similarly large number.

Basically the choice between Intel and AMD in the context of in-chip vulnerabilities comes down to whether one feels better choosing a chip with known vulnerabilities + significant effort to mitigate or a chip without known vulnerabilities and without significant efforts at mitigation. In both cases, unknown vulnerabilities are probably equal.

To put it another way, building a computer is largely a consumer process not a technical one. The biggest security risk is software you download and run, not hardware flaws (e.g. rowhammer)

Re: Meltdown, aka “Dear Intel, you suck”

#114
post #57

Earlier quoted context omitted.

QNX does map it's kernel onto high end of user VM space. Due to how i386 TLB works (ie. no ASID) doing that is essentially required to get reasonable performance, micro kernel or not.

What about on ARM?

Has QNX been ported to ARM? Interesting!

edit: apparently it has been:

http://www.qnx.com/developers/docs/6.5.0/index.jsp?topic=%2F...

Re: Meltdown, aka “Dear Intel, you suck”

#115
post #103
post #100

Is it the right time to call out the fundamental wrongness of Intel(/Apple/Microsoft/etc) outrage narratives? I mean I get it: large corporations (1) don't necessarily have my interests at heart; (2) are not able to perfectly execute (on extremely large and complicated) products and systems. um. This is as radical as taking a stand that the sun sets in the west. I like HN because of the promise that people think just…

>I just wish there was just some corner of the internet where this wasn't the dominant trend and I had hoped it was here on HN You're not going to find that, because taking the path of least intellectual and emotional resistance is just human nature. There is a positive feedback loop with outrage narratives that feeds people's ego and sense of in-group superiority, where one either feels empowered by agreement, or fe…

Metafilter seems to be better about this stuff than we are here. At least, whenever I read it, the responses seem more thoughtful.

Re: Meltdown, aka “Dear Intel, you suck”

#116
post #100

Is it the right time to call out the fundamental wrongness of Intel(/Apple/Microsoft/etc) outrage narratives? I mean I get it: large corporations (1) don't necessarily have my interests at heart; (2) are not able to perfectly execute (on extremely large and complicated) products and systems. um. This is as radical as taking a stand that the sun sets in the west. I like HN because of the promise that people think just…

The three big BSDs aren't exactly obscure, they might not have the highest server market share compared to windows and linux but they are the next on the list and often a primary choice for a variety of companies critical infrastructure, the most commonly sighted example these days is netflix.

I think the outrage is justified.

Re: Meltdown, aka “Dear Intel, you suck”

#117
post #94

Earlier quoted context omitted.

...but if it is "so obvious" - why has it taken ~20 years to discover it (publically)?

It’s been discussed for years by people who didn’t need to see the exploit to know that it had to be there. Sane people have been avoiding timesharing for critical work on x86 since Core 2. Life-safety work has no business in a public cloud.

This is a recurring pattern that just blows my mind: typically some small, often academic, group knows about some problem or potential problem that everybody else is ignoring until it becomes un-ignorable.

Anthopogenic climate change falls into this category.

I have to wonder, first, what sort of obvious stupid self-destructive things am I doing right now but ignoring. And second, how can we build systems that systematically take this into account? Is there some way to short-cut the process and find and fix problems in the early stages? Or better yet, design our systems so that they don't have the problems from the start?

Re: Meltdown, aka “Dear Intel, you suck”

#118
post #72
post #52

Earlier quoted context omitted.

Well, there is the ME for one, an omnipotent, mandatory backdoor. Then there are _many_ undocumented opcodes. What does 0f0d00 do? What 0f78c0? What dbe0? I can continue for a very long time. These are just some known unknowns. If you still need more reasons, they are uncooperative when it comes to certain other firmware blobs. If you are open to arguments, there are many good reasons to take a negative stance toward…

To be fair gmail flags basically any code, if it's zipped i've found it only needs to vaguely resemble code. basically gmail is only safe for sending image formats and document formats that it knows of and don't contain macros, then it's just a crapshoot that you don't get matched a false positive. Gmail is far from developer friendly anymore.

> Gmail is far from developer friendly anymore.

Was it ever?

Re: Meltdown, aka “Dear Intel, you suck”

#119
post #69

Earlier quoted context omitted.

Intent matters, at least to me. This does not seem to be a case like VW's diesel-emissions shenanigans.

The problem still is: one of the units responsible for increasing the processor performance was not working correctly. So the increased performance of the processor was obtained by not working correctly. That qualifies as cheating - if not by intent but then by nature of the design. It remains to be investigated how much of the security implications of their design choices was or could have been known to Intel. The f…

No, it just doesn’t. You’re diluting the meaning of that term to irrelevance. There are plenty of other words that adequately describe what happened - sloppy, careless, short-sighted. Cheating isn’t one of them.

Re: Meltdown, aka “Dear Intel, you suck”

#120
post #72

Earlier quoted context omitted.

To be fair gmail flags basically any code, if it's zipped i've found it only needs to vaguely resemble code. basically gmail is only safe for sending image formats and document formats that it knows of and don't contain macros, then it's just a crapshoot that you don't get matched a false positive. Gmail is far from developer friendly anymore.

> Gmail is far from developer friendly anymore. Was it ever?

Well, not positively, but there was a time when it didn't block you from zipping up a little snippet of code and sending it to someone or saving it a draft when your in a hurry.
Post reply on HN