Live data from Hacker News

Meltdown, aka “Dear Intel, you suck”

marc.info

141–150 of 176 posts

Re: Meltdown, aka “Dear Intel, you suck”

#141
post #116

Earlier quoted context omitted.

The three big BSDs aren't exactly obscure, they might not have the highest server market share compared to windows and linux but they are the next on the list and often a primary choice for a variety of companies critical infrastructure, the most commonly sighted example these days is netflix. I think the outrage is justified.

Don't mistake this as OpenBSD's concern for all BSD's. This is just OpenBSD rant because they isolated themselves by not respecting embargoes in the past. Some ARM CPU's are also vulnerable by the way.

That's an interesting point RE OpenBSD, especially if FreeBSD and NetBSD were included (which I do not know), I suspect this was just down to plain irresponsible incompetence though.

...I've no idea what your ARM comment has to do with it though. Meltdown is Intel specific.

A relevant question however might be who coordinated the work between june 2017 and now for Meltdown mitigations? Project zero at google discovered it, but did they hand over the responsibility to Intel or decide who else to inform themselves?

Re: Meltdown, aka “Dear Intel, you suck”

#142

Earlier quoted context omitted.

I love how that link just completely times out.

Works just fine for me? Which link?

The link [1] that you posted does not load for me either. I get Cloudflare's Error 504 Gateway time-out.

[1]: https://www.eternum.io/ipfs/QmQU1bCPsg7VY5puKqH6wZfAv1ZWBteK...

Re: Meltdown, aka “Dear Intel, you suck”

#143

Hi I'm a mostly average Linux user just now learning about these hardware vulnerabilities as I'm planning on building a new computer. What new processor should I buy that has the best chance of being safe when all this dust clears? I first posted this question on a thread about Intel ME. Have processors always been this tricky security-wise or are these low level exploits we're finding a recent phenomena?

MC68030. /s

Re: Meltdown, aka “Dear Intel, you suck”

#144

Earlier quoted context omitted.

I am also increasingly desperate for an internet place to read and discuss things in good faith. When HN started to go downhill I shifted to Twitter, but Twitter is like poison. Perhaps we can create a new place?

Could you estimate for us when "HN started to go downhill"?

I suppose it's different for everyone, but for me the discussion quality started to fade around 2013.

Re: Meltdown, aka “Dear Intel, you suck”

#145
post #105
post #57

Earlier quoted context omitted.

QNX does map it's kernel onto high end of user VM space. Due to how i386 TLB works (ie. no ASID) doing that is essentially required to get reasonable performance, micro kernel or not.

If the kernel has no sensitive state (believable for a microkernel), what matters is whether it maps the physical memory in its kernel space.

QNX 6.5 apparently maps first 256MB of physical memory into kernel space at fixed location. Also I believe that QNX's kernel memory contains region that maps to pages of user space memory of other processes (as part of the message passing mechanism, but I'm not exactly sure that I understand correctly how it actually works).

Re: Meltdown, aka “Dear Intel, you suck”

#146
post #95

Hi I'm a mostly average Linux user just now learning about these hardware vulnerabilities as I'm planning on building a new computer. What new processor should I buy that has the best chance of being safe when all this dust clears? I first posted this question on a thread about Intel ME. Have processors always been this tricky security-wise or are these low level exploits we're finding a recent phenomena?

You could go with AMD which is seemingly immune to Meltdown, but apparently someone already found a security flaw with their PSP (aka their own Intel ME).

I've seen rumors that new bios/uefi versions have a toggle to disable PSP.

So AMD looks like a fair choice if this is true.

Re: Meltdown, aka “Dear Intel, you suck”

#147
post #69

Earlier quoted context omitted.

The problem still is: one of the units responsible for increasing the processor performance was not working correctly. So the increased performance of the processor was obtained by not working correctly. That qualifies as cheating - if not by intent but then by nature of the design. It remains to be investigated how much of the security implications of their design choices was or could have been known to Intel. The f…

No, it just doesn’t. You’re diluting the meaning of that term to irrelevance. There are plenty of other words that adequately describe what happened - sloppy, careless, short-sighted. Cheating isn’t one of them.

You can easily cheat, without bad faith, by being sloppy or careless. You can also cheat in bad faith and call it being sloppy or careless. Breaking rules often has nothing to do with intent.

Re: Meltdown, aka “Dear Intel, you suck”

#148
post #142

Earlier quoted context omitted.

Works just fine for me? Which link?

The link [1] that you posted does not load for me either. I get Cloudflare's Error 504 Gateway time-out. [1]: https://www.eternum.io/ipfs/QmQU1bCPsg7VY5puKqH6wZfAv1ZWBteK...

Hmm yeah, it's doing that for me now too. I'm afraid the IPFS node is a bit unstable, I've restarted it and hopefully it'll work better, thanks.

Any other IPFS node will work just as well, such as https://ipfs.io/ipfs/QmQU1bCPsg7VY5puKqH6wZfAv1ZWBteKTCgHRKz....

Re: Meltdown, aka “Dear Intel, you suck”

#149
post #94

Earlier quoted context omitted.

It’s been discussed for years by people who didn’t need to see the exploit to know that it had to be there. Sane people have been avoiding timesharing for critical work on x86 since Core 2. Life-safety work has no business in a public cloud.

This is a recurring pattern that just blows my mind: typically some small, often academic, group knows about some problem or potential problem that everybody else is ignoring until it becomes un-ignorable. Anthopogenic climate change falls into this category. I have to wonder, first, what sort of obvious stupid self-destructive things am I doing right now but ignoring. And second, how can we build systems that system…

The key thing to take into account here is that for every one of those early warnings that turn out to be true there's also a plethora of speculation that never amounts to anything.

Re: Meltdown, aka “Dear Intel, you suck”

#150
post #121

Earlier quoted context omitted.

Late December, i.e. a week or so before the cat actually got let out of the bag, and probably around a fortnight's notice until the originally planned coördinated announcement date. * https://news.ycombinator.com/item?id=16074531 That is hardly enough time, considering that it is likely a holiday period for most of the people concerned, to prepare what needed to be prepared. Google and Intel gave themselves six month…

> That is hardly enough time, considering that it is likely a holiday period for most of the people concerned, to prepare what needed to be prepared. Google and Intel gave themselves six months, in contrast, and they gave Ubuntu since November 2017. Correct, but it’s significantly better than OpenBSD’s timeline (which learnt about it from the media). Mitigation for Meltdown is possible within of a week, or two. It re…

No, it is not significantly better. Contrasted with the months that the likes of Microsoft, Ubuntu, and (going by what Paolo Bonzini has already said on Hacker News) RedHat got, FreeBSD and OpenBSD were in practical terms in the same boat. The difference of a week, when that week is Christmastide, is insignificant when put alongside those.
Post reply on HN