Live data from Hacker News

How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

techcrunch.com

21–30 of 71 posts

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#21
post #11

Earlier quoted context omitted.

> Why? Because the fallout will cost billions over the next years. Intel as a company due to class-action lawsuits, recalls, rebates, and the shareholders because the drop in stock value after the announcement will cost them quite a chunk of money. In addition, more long-term, I sincerely hope that the cloud vendors (and maybe even Apple!) recognize that their total dependence on Intel (and NVIDIA in deep learning...…

Unclear that diversifying helps solve this sort of problem. More vendors could lead to the same number of bugs, but less investment in quality control per product e.g. if you make $1b and spend 1% on quality control, then you spend $10m checking your product for bugs. If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much…

> If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much of your budget on quality control.

But there's a much smaller attack surface and the incentives for attackers are significantly changed. Homogeneity is always more vulnerable to disaster, whether we're talking about food supply or chips.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#22
post #20
post #14

Saved you a click: by starting a shared Slack for their teams to collaborate. Neat factoid but this article is not exactly information-dense.

I don't think the actual technical "how" is of much importance so the article doesn't spend much time on it. They communicated effectively, and more important openly, over company boundaries. Many tools would have worked for that. This is about "how" they banded together to reduce their disadvantage compared to the big cloud providers that had advance warning and insider knowledge/access to the vendors long before th…

Correct. It's the ability to share documents and conversation snippets provided by vendors, as well as curating and summarizing the significant amount of information available.

I've never seen an exploit that involves microcode updates, compiler fixes, kernel patches, and KVM/Xen updates all together. The number of moving parts is staggering.

Being able to filter and summarize that across company boundaries has helped me both understand and more effectively work to mitigate this problem.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#24
post #11

Earlier quoted context omitted.

> Why? Because the fallout will cost billions over the next years. Intel as a company due to class-action lawsuits, recalls, rebates, and the shareholders because the drop in stock value after the announcement will cost them quite a chunk of money. In addition, more long-term, I sincerely hope that the cloud vendors (and maybe even Apple!) recognize that their total dependence on Intel (and NVIDIA in deep learning...…

Unclear that diversifying helps solve this sort of problem. More vendors could lead to the same number of bugs, but less investment in quality control per product e.g. if you make $1b and spend 1% on quality control, then you spend $10m checking your product for bugs. If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much…

> Unclear that diversifying helps solve this sort of problem.

At least having the option of another vendor as a fallback (e.g. in case there's a severe RCE vulnerability in ME/PSP) is a better alternative than having to shutter your entire business.

I would not be surprised if these management engines have a backdoor that can be invoked from a guest VM... and then an all-Intel (or all-AMD) shop has a massive problem.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#25
post #7

Earlier quoted context omitted.

The CEO should probably spend some time in the pokey for all the stock he sold between when he knew about this problem, and when it was publicly known. I'm curious how many other Intel employees sold stock in the same period.

This has been debunked already - CEO sold the maximum amount of company stock he could from his yearly award every 4th quarter for the last 4 (5?) years in a row.

He is not inspiring much confidence in the future of INTC.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#27
post #11

Earlier quoted context omitted.

> Why? Because the fallout will cost billions over the next years. Intel as a company due to class-action lawsuits, recalls, rebates, and the shareholders because the drop in stock value after the announcement will cost them quite a chunk of money. In addition, more long-term, I sincerely hope that the cloud vendors (and maybe even Apple!) recognize that their total dependence on Intel (and NVIDIA in deep learning...…

Unclear that diversifying helps solve this sort of problem. More vendors could lead to the same number of bugs, but less investment in quality control per product e.g. if you make $1b and spend 1% on quality control, then you spend $10m checking your product for bugs. If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much…

> e.g. I'm pretty sure no white-hat security researcher has checked for security problems in the cheap wifi light switches I bought on Amazon.

But isn't this also applicable to the other side? As in, black hats have less incentives to research vulnerabilities in less popular products (security through minority). I'm not certain how this balances out.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#28
post #7

Earlier quoted context omitted.

This has been debunked already - CEO sold the maximum amount of company stock he could from his yearly award every 4th quarter for the last 4 (5?) years in a row.

It's not clear to me that he's behaving like he did in the past: > According to filings, on Nov. 29, Krzanich exercised and sold 644,135 options and sold an additional 245,743 shares that he already owned. -- https://www.bloomberg.com/news/articles/2018-01-04/intel-ceo... Sure, he sold most of his 279k grant, just like he sold most of his previous (much smaller) grants, but he also flipped a huge pile of options. Thi…

Mottley Fool article by Ashraf Eassa on December 19 [0] supports your position that it wasn't just routine behavior:

>However, there were two transactions that Krzanich reported in that Form 4 filing that I thought were more notable than typical stock option exercises and subsequent share sales. Let's take a closer look. ...

(Assuming that Ashraf called this without inside knowledge of what Intel had already disclosed by that date to selected 3rd parties.)

[0] https://www.fool.com/investing/2017/12/19/intels-ceo-just-so...

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#29

The more I know about how Intel has managed the information, the less I trust them. What a disaster. CEO and all the Press and Communication team of Intel should be fired

It's not clear to me what the best approach is here. The wider the circle of those who know, the more likely it is that there will eventually be a leak. Three can keep a secret if two are dead and all that.

Exactly. I assume if one of the smaller providers like Linode found an internal vulnerability that they thought was a big security risk to have widely know and had 3 giant customers and a large number of smaller customers, they’d work directly with the giant customers in advance in the same way.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#30
post #11

Earlier quoted context omitted.

Unclear that diversifying helps solve this sort of problem. More vendors could lead to the same number of bugs, but less investment in quality control per product e.g. if you make $1b and spend 1% on quality control, then you spend $10m checking your product for bugs. If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much…

> e.g. I'm pretty sure no white-hat security researcher has checked for security problems in the cheap wifi light switches I bought on Amazon. But isn't this also applicable to the other side? As in, black hats have less incentives to research vulnerabilities in less popular products (security through minority). I'm not certain how this balances out.

Cheap products can be quite popular. It's probably fine until that cheap item you bought goes viral on facebook, or there is a single upstream vendor that is hugely successful. No idea either, only statistics would tell.
Post reply on HN