Live data from Hacker News

Meltdown Update Kernel doesnt boot

bugs.launchpad.net

111–120 of 205 posts

Re: Meltdown Update Kernel doesnt boot

#111
post #86
post #20

Would this entire Meltdown/Spectre thing count as the biggest mess-up of computing history? When yesterday the PoC repo was posted here, the spy.mp4 demo video gave me some chills. And now I can't update my OS before making an installation USB because Canonical can't just follow Linus' releases. Thanks.

I think that title is currently held (deserved or not) by null pointers. Tbh it’s not the most meaningful of statements, but it’s food for thought.

[deleted]

Re: Meltdown Update Kernel doesnt boot

#112
post #46

Earlier quoted context omitted.

Depends on the recall, the GM ignition recall was done on an independent appt basis. (besides you should not be taking your car to the dealer if you value your wallet)

You need a new dealer...most have greatly improved customer service experiences these days, and many independents are no panaceas...

Dealers make almost zero margin on car sales(aside from used and trade-in shenanigans). The majority of their margin comes from services so they'll happily gouge you on them.

Re: Meltdown Update Kernel doesnt boot

#113
post #47

Earlier quoted context omitted.

>Would this entire Meltdown/Spectre thing count as the biggest mess-up of computing history? When yesterday the PoC repo was posted here, the spy.mp4 demo video gave me some chills. It must be up there amongst the greats, probably with the "halt and catch fire" op code. Normally they just patch this stuff with microcode and never really tell anybody, this time that won't work. I'm not entirely convinced it was a mist…

I think it's absolutely unreasonable to imply that this was intentional. Besides the massive amount of complexity these systems have, there are plenty of "legitimate" places to hide backdoors, instead of in a performance architecture decision. Keep in mind that whatever "evil agencies" would have asked for this would most likely find themselves vulnerable, and nobody would sign off on. I do agree, however, the "secur…

The Intel Management Engine is a backdoor. Speed variations in speculative execution are an inherent property of the technology. Until recently, few people thought this was exploitable, and it took a lot of work to figure out how to exploit this.

Re: Meltdown Update Kernel doesnt boot

#114
post #2

it's the fault of Intel, why don't they recall all the CPU? just like vehicle company

Most vehicle recalls are not of the form: return your vehicle, we give you a new fixed one; but rather: bring your vehicle to one of our dealers and they'll perform some action to repair the defect.

The later is pretty analogous to issuing firmware and OS patches to mitigate the flaw.

Re: Meltdown Update Kernel doesnt boot

#115

Earlier quoted context omitted.

I think it's absolutely unreasonable to imply that this was intentional. Besides the massive amount of complexity these systems have, there are plenty of "legitimate" places to hide backdoors, instead of in a performance architecture decision. Keep in mind that whatever "evil agencies" would have asked for this would most likely find themselves vulnerable, and nobody would sign off on. I do agree, however, the "secur…

Well, I read somewhere the other day that this form of error/attack was conceived of in the academic literature back in 1992. I won’t believe it’s intentional without evidence in that direction, but this is conceivably the kind of obscure/complex attack you’d expect of a state actor.

This has been a known issue in xbox 360 hardware since about 2010.

It just keeps popping up, someone finally thought to weaponize it.

Re: Meltdown Update Kernel doesnt boot

#116

Earlier quoted context omitted.

I think it's absolutely unreasonable to imply that this was intentional. Besides the massive amount of complexity these systems have, there are plenty of "legitimate" places to hide backdoors, instead of in a performance architecture decision. Keep in mind that whatever "evil agencies" would have asked for this would most likely find themselves vulnerable, and nobody would sign off on. I do agree, however, the "secur…

The Intel Management Engine is a backdoor. Speed variations in speculative execution are an inherent property of the technology. Until recently, few people thought this was exploitable, and it took a lot of work to figure out how to exploit this.

You do realize those are ideal properties for a backdoor, don't you? If you were writing the spec for a dream backdoor, you would write that down. The only way you could improve it would be "everyone thinks it's impossible, and they never figure it out."

Re: Meltdown Update Kernel doesnt boot

#117
post #84
post #55

Earlier quoted context omitted.

Are you suggesting that we recall the great bulk of modern CPU's? Like, literally gut everyone's computers, including those in data centers and running critical infrastructure, until replacements are eventually manufactured? Or did you mean something else?

I'd think it'd be reasonable to get a refund in some manner, provided you could provide proof-of-purchase for the CPU in question. I wouldn't expect them to replace any CPU, unless it was manufactured recently and still being manufactured. But a refund in some capacity? That's reasonable, I think. In the meantime, we would have to settle for the software fixes.

I think this is pretty weird thing to talk about, because it's kinda pointless. Do I think Intel ought to refund us somehow? Hell yeah I do, especially given the fact that I have bought a laptop with Intel processor recently and why even bother buying products with a warranty if any fatal design flows don't qualify as refundable anyway? Do I believe Intel will refund or replace something? Of course not, it's hardly even realistic. Even if they wanted to (which they surely don't) what kind of loan do they have to get to afford even a partial refund of every single Intel CPU out there?

Re: Meltdown Update Kernel doesnt boot

#118
post #99

Earlier quoted context omitted.

A null pointer doesn't hold a reference, though.

It does if you have something at 0x0. Or, to put it another way, I have no clue to what you're referring--what do references have to do with "The Billion Dollar Mistake"[0]? [0]: https://en.wikipedia.org/wiki/Tony_Hoare#Apologies_and_retra... EDIT: my apologies, that joke was actually pretty good.

I think it was supposed to be a pun on "hold". As for the word "reference", your own link uses it.

Re: Meltdown Update Kernel doesnt boot

#119

Earlier quoted context omitted.

Boxed Intel processors carry a 3 year warranty. It certainly seems reasonable for everyone who bought a CPU within the last 3 years to expect a warranty replacement with the manufacturer defect fixed. In the EU virtually every product comes with a 2 year warranty. So every CPU sold in the EU in the last two years should be replaced for free by Intel, even through OEMs. I wonder what potential class action lawsuits In…

Any sufficiently complex CPU surely contains some number of defects, perhaps even serious security defects, just as any sufficiently complex piece of software contains bugs and security holes. I wouldn't be surprised if someone tries to sue Intel over this, or even if they win, but this is way outside the scope of what a warranty would traditionally cover, which in the case of a CPU would be hardware failure. If a wa…

Of course the cost of producing products that actually perform at the level they're advertised to perform is passed onto the consumer, regardless of regulation.

Re: Meltdown Update Kernel doesnt boot

#120
post #57

This arch/x86/events/intel/ds.c fix is unlikely to have rendered too many things unbootable. I missed ds.c entirely when doing the original implementation. I can't fault the nice folks at Canonical for mis-merging a tiny hunk like this. It really only affects pretty specific hardware anyway.

What hardware does it effect?

From the bug it looks like a smattering of Xeons, Celerons, i5s, not sure what's "specific" about it from first glance.
Post reply on HN