Live data from Hacker News

How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

techcrunch.com

31–40 of 71 posts

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#31
post #7

Earlier quoted context omitted.

This has been debunked already - CEO sold the maximum amount of company stock he could from his yearly award every 4th quarter for the last 4 (5?) years in a row.

It's not clear to me that he's behaving like he did in the past: > According to filings, on Nov. 29, Krzanich exercised and sold 644,135 options and sold an additional 245,743 shares that he already owned. -- https://www.bloomberg.com/news/articles/2018-01-04/intel-ceo... Sure, he sold most of his 279k grant, just like he sold most of his previous (much smaller) grants, but he also flipped a huge pile of options. Thi…

I would do the same thing no matter the stock. It is stupid to keep all your eggs in one basket (as others are saying about userland all through this thread).

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#32
post #11

Earlier quoted context omitted.

Unclear that diversifying helps solve this sort of problem. More vendors could lead to the same number of bugs, but less investment in quality control per product e.g. if you make $1b and spend 1% on quality control, then you spend $10m checking your product for bugs. If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much…

> Unclear that diversifying helps solve this sort of problem. At least having the option of another vendor as a fallback (e.g. in case there's a severe RCE vulnerability in ME/PSP) is a better alternative than having to shutter your entire business. I would not be surprised if these management engines have a backdoor that can be invoked from a guest VM... and then an all-Intel (or all-AMD) shop has a massive problem.

Intel ME drivers are not loaded into a VM, the devices are not exposed and the ME MSRs are also not exposed.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#33

Earlier quoted context omitted.

It's not clear to me what the best approach is here. The wider the circle of those who know, the more likely it is that there will eventually be a leak. Three can keep a secret if two are dead and all that.

Exactly. I assume if one of the smaller providers like Linode found an internal vulnerability that they thought was a big security risk to have widely know and had 3 giant customers and a large number of smaller customers, they’d work directly with the giant customers in advance in the same way.

I am resisting the urge to make a Linode and ColdFusion joke.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#34
post #11

Earlier quoted context omitted.

> Why? Because the fallout will cost billions over the next years. Intel as a company due to class-action lawsuits, recalls, rebates, and the shareholders because the drop in stock value after the announcement will cost them quite a chunk of money. In addition, more long-term, I sincerely hope that the cloud vendors (and maybe even Apple!) recognize that their total dependence on Intel (and NVIDIA in deep learning...…

Unclear that diversifying helps solve this sort of problem. More vendors could lead to the same number of bugs, but less investment in quality control per product e.g. if you make $1b and spend 1% on quality control, then you spend $10m checking your product for bugs. If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much…

AMD chips do not need PTI. All the performance hits people are talking about right now would be irrelevant on a cloud farm that used AMD CPUs for their hosts. If any such cloud farms exist, they had better be declaring that loud and proud; I expect there will be a lot of people looking to jump ship.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#35

Earlier quoted context omitted.

> Unclear that diversifying helps solve this sort of problem. At least having the option of another vendor as a fallback (e.g. in case there's a severe RCE vulnerability in ME/PSP) is a better alternative than having to shutter your entire business. I would not be surprised if these management engines have a backdoor that can be invoked from a guest VM... and then an all-Intel (or all-AMD) shop has a massive problem.

Intel ME drivers are not loaded into a VM, the devices are not exposed and the ME MSRs are also not exposed.

> and the ME MSRs are also not exposed.

This is the core question: is this isolation absolutely perfect, or can it be pierced in any way? Something on a severity level like Spectre/Meltdown - people would have laughed you off the stage half a year ago when you told 'em you could read kernel memory from Javascript without exploiting both the browser and the kernel - is IMHO certain to be present in either of the "management" solution, and I'd like to be prepared when the bomb explodes.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#36
post #6

Prgmr.com has been participating on the Slack channel this article mentions. Being able to share notes gleaned from reaching out to vendors and sort through the information and mitigations for Spectre and Meltdown has been a huge help.

Do you think the communication channel will persist beyond the current vulnerability? E.g. give it a name, allow other cloud providers to join?

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#38

The more I know about how Intel has managed the information, the less I trust them. What a disaster. CEO and all the Press and Communication team of Intel should be fired

It's not clear to me what the best approach is here. The wider the circle of those who know, the more likely it is that there will eventually be a leak. Three can keep a secret if two are dead and all that.

This proverb is mostly not true. I've worked in high-secrecy areas and everybody keeps their mouth shut because they're terrified of the consequences to their career.

Three can keep a secret if two are bound by an NDA is closer.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#39

Earlier quoted context omitted.

It's not clear to me what the best approach is here. The wider the circle of those who know, the more likely it is that there will eventually be a leak. Three can keep a secret if two are dead and all that.

Exactly. I assume if one of the smaller providers like Linode found an internal vulnerability that they thought was a big security risk to have widely know and had 3 giant customers and a large number of smaller customers, they’d work directly with the giant customers in advance in the same way.

I was a Linode customer back when there was a security incident where everyone found out on Reddit before the company bothered to tell anyone. And then once news did come out they never said (a) what happened or (b) what steps were taken to prevent it happening again.

I am very reluctant now to trust the little guys with anything remotely mission critical.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#40

Earlier quoted context omitted.

Why? Intel made billions last year. They will make billions this year. They will make billions next year.

> Why? Because the fallout will cost billions over the next years. Intel as a company due to class-action lawsuits, recalls, rebates, and the shareholders because the drop in stock value after the announcement will cost them quite a chunk of money. In addition, more long-term, I sincerely hope that the cloud vendors (and maybe even Apple!) recognize that their total dependence on Intel (and NVIDIA in deep learning...…

The intel CEO took over in 2012 - some of these vulnerabilities go back as far as the Pentium Pro (Meltdown) and the other one, effects (I believe) as far back as the original Pentium (Spectre) - why would you fire someone for something that happened under a predecessors leadership (Andy Grove, in this case was CEO when the Meltdown attack was added) - it makes no sense - I see nothing here that doesnt jive up with similar efforts with other bugs.
Post reply on HN