Live data from Hacker News

How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

techcrunch.com

61–70 of 71 posts

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#61

Earlier quoted context omitted.

It's not clear to me what the best approach is here. The wider the circle of those who know, the more likely it is that there will eventually be a leak. Three can keep a secret if two are dead and all that.

There was a leak. Typing this from Ubuntu - still no updated kernels yet.

Should be coming on/before Tuesday: https://insights.ubuntu.com/2018/01/04/ubuntu-updates-for-th...

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#62
post #45

Earlier quoted context omitted.

You do know that INTC is up compared to 1 month ago? If it didn't drop that much on the initial announcement, why would it plummet in the coming months?

Because there is no quantifiable impact yet. Right now all that's known is "mh, it's bad, but the OS vendors are patching it"... now give the situation a couple weeks to brew, wait for more data on the CPU impact of these patches and the inevitable lawsuits. Plus, Intel might want to think about delaying the next CPU releases (or introduce a new stepping of existing CPUs) to fix the bugs in hardware... all stuff that…

If the market agreed with you that Intel will suffer greatly in the future due to Meltdown/Spectre the price would have dropped already. Of course you might be correct and the market wrong. You’re short Intel, right?

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#63
post #11

Earlier quoted context omitted.

Unclear that diversifying helps solve this sort of problem. More vendors could lead to the same number of bugs, but less investment in quality control per product e.g. if you make $1b and spend 1% on quality control, then you spend $10m checking your product for bugs. If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much…

> If the market fragments into 10 $100m vendors, then to get the same amount of money spent checking each chip for bugs, you'd have to spend 10x as much of your budget on quality control. But there's a much smaller attack surface and the incentives for attackers are significantly changed. Homogeneity is always more vulnerable to disaster, whether we're talking about food supply or chips.

And quality is not directly a function of money spent. Customers will start demanding to see the machine checked proofs that your hardware is correct. Intel has been cowboy coding CPUs for way too long.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#64

Earlier quoted context omitted.

Intel ME drivers are not loaded into a VM, the devices are not exposed and the ME MSRs are also not exposed.

> and the ME MSRs are also not exposed. This is the core question: is this isolation absolutely perfect, or can it be pierced in any way? Something on a severity level like Spectre/Meltdown - people would have laughed you off the stage half a year ago when you told 'em you could read kernel memory from Javascript without exploiting both the browser and the kernel - is IMHO certain to be present in either of the "mana…

I don’t think any serious security person would have laughed you off for mentioning side channel attacks.

No isolation is perfect but and that is an important but for virtualization you have much higher control over what instruction you allow through so an attach which is specific to ME isn’t likely.

That said you can have a side channel attack that allows you to compromise the hypervisor and from it you can jump to the ME but this is a different story.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#65
post #14

Saved you a click: by starting a shared Slack for their teams to collaborate. Neat factoid but this article is not exactly information-dense.

And now there are "Tier 3" companies that didn't get invited to the slack channel.

It all helps big get bigger and making life harder for smaller companies. Not a great setup for a healthy competition.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#66

Earlier quoted context omitted.

Exactly. I assume if one of the smaller providers like Linode found an internal vulnerability that they thought was a big security risk to have widely know and had 3 giant customers and a large number of smaller customers, they’d work directly with the giant customers in advance in the same way.

I was a Linode customer back when there was a security incident where everyone found out on Reddit before the company bothered to tell anyone. And then once news did come out they never said (a) what happened or (b) what steps were taken to prevent it happening again. I am very reluctant now to trust the little guys with anything remotely mission critical.

[deleted]

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#67

Earlier quoted context omitted.

Why? Intel made billions last year. They will make billions this year. They will make billions next year.

> Why? Because the fallout will cost billions over the next years. Intel as a company due to class-action lawsuits, recalls, rebates, and the shareholders because the drop in stock value after the announcement will cost them quite a chunk of money. In addition, more long-term, I sincerely hope that the cloud vendors (and maybe even Apple!) recognize that their total dependence on Intel (and NVIDIA in deep learning...…

> Because the fallout will cost billions over the next years.

Doubtful. Intel has a near monopoly in data centers in 2017. They will have a near monopoly in data centers in 2018 and 2019 I predict as well.

Really very few things they can do to lose their business at this point.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#68

Earlier quoted context omitted.

It's not clear to me what the best approach is here. The wider the circle of those who know, the more likely it is that there will eventually be a leak. Three can keep a secret if two are dead and all that.

There was a leak. Typing this from Ubuntu - still no updated kernels yet.

It wasn't so much a leak as someone putting two and two together and the cat getting out of the bag.

Anyway, this is a nonsense argument in the context of the thread. They tried to keep things quiet by limiting the size of the circle, among other things. Their attempts at secrecy did not entirely succeed, although they made it 90% of the way to the embargo date without things coming out. Their inability to make it 100% of the way does not inform us at all about whether they should indeed have limited the circle of those who knew.

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#69

The more I know about how Intel has managed the information, the less I trust them. What a disaster. CEO and all the Press and Communication team of Intel should be fired

Shouldn't the CEO be investigated for insider trading?

Re: How Tier 2 cloud vendors banded together to cope with Spectre and Meltdown

#70
post #52

Note that Google released information a week early, giving attackers a leg up in attacking these cloud providers, as opposed to Google giving the cloud providers the information immediately, which would have helped them defend themselves. But, surprise: Google is their competitor. Google is basically the new Microsoft, except Microsoft could actually design working products when it was evil.

What's with these random jabs at companies, you are just trying to create a culture of irrational dislike. I don't even care if you attack Google but everytime you do so, you have to cite exactly why you are doing it. Not some nebulous "oh they cant even make a single working product" which is objectively false and just provocation.

One, you're attributing something I never said, and two, my actual claim is not objectively false. Three, I don't have to do anything, much less prove what is otherwise easy to find out via Googling. And four, it's not irrational dislike, it's dislike based on personal experience and observation. Five, it should be pretty obvious exactly why i'm attacking Google, it doesn't need citing (unless the reader can't put two and two together, vis a vie "Google uses its privileged embargo status to disseminate sensitive information in a way that harms its competitors")
Post reply on HN