Live data from Hacker News

Intel Security Issue Update: Addressing Reboot Issues

newsroom.intel.com

31–40 of 129 posts

Re: Intel Security Issue Update: Addressing Reboot Issues

#31
post #15

“We have received reports from a few customers of higher system reboots after applying firmware updates.” What does higher mean here?

more frequent

With the implication that random reboots of a lesser, but non-zero frequency are okay, it's at least expected?

Odd wording for sure.

Re: Intel Security Issue Update: Addressing Reboot Issues

#32
post #16

This is -- to say the least -- frustrating. First, the busted microcode is still available on the Intel Download Center[1], without any warning that they recommend that you not, in fact, install it. Second, the press release is still being evasive: they have not merely "received reports"; they in fact know that it's causing issues, and the press release is avoiding the much stronger language that Intel is giving priv…

Why should they bother communicating clearly with their customers? Who are those customers going to turn to? AMD? ARM? Between Intel's numerous CPU bugs that they refused to refund customers for and ME, it's crystal clear what Intel thinks about their customers.

Customers actually could turn to AMD... their offerings are very competitive right now.

Re: Intel Security Issue Update: Addressing Reboot Issues

#33

This is -- to say the least -- frustrating. First, the busted microcode is still available on the Intel Download Center[1], without any warning that they recommend that you not, in fact, install it. Second, the press release is still being evasive: they have not merely "received reports"; they in fact know that it's causing issues, and the press release is avoiding the much stronger language that Intel is giving priv…

The smiling face of VP Navin Shenoy next to each Intel Meltdown press release is highly inappropriate!

(in the HN news article linked above https://newsroom.intel.com/news/intel-security-issue-update-... )

Re: Intel Security Issue Update: Addressing Reboot Issues

#35
post #18

Well this promises to be fun, especially for cloud providers (and those running instances on the cloud, who now potentially get to suffer through host instability)

Intel's adaptation of Netflix's Chaos Monkey [0]? [0]: https://en.wikipedia.org/wiki/Chaos_Monkey

I was thinking the same thing as I read this. “Chaos engineering” has served some customers very well here.

From speaking in my circles, I get the impression that those of us without our own data centers to worry about are much better off than those who do.

Re: Intel Security Issue Update: Addressing Reboot Issues

#36
post #13

I think it's a bit ironic that the text, in a sense, blames Google for these problems by calling them the "Google Project Zero Exploits" as if Google was some sort of cyber crime syndicate using their evil powers to exploit intel.

Yeah I thought that was interesting too. I think they are most likely name dropping Google just because they want to reinforce whatever type of association with Google that they can get. Lots of people won't register this as a bad thing per se, and will just think "Wow it's super cool that Intel is working with The Googles on something".

As developers, we should know this phenomenon well by now, as it's dictated an ever-increasing portion of our toolchain. "Oh, you say Google uses this thing?! I use it too then! Google and me are best buds!". (This applies equally to Facebook, and to a lesser extent, Amazon. Compare one of my son's favorite YouTube videos at [0]).

Alternatively, they may want customers to think "Oh boy you have to be a super genius guy like the Googles to beat up Intel so this isn't a big deal", or "How could Google do this to a nice company like Intel".

So many possibilities, but really all of them turn out well for Intel.

[0] https://youtu.be/6x0yWfmh-zk?t=19

Re: Intel Security Issue Update: Addressing Reboot Issues

#37
post #16

This is -- to say the least -- frustrating. First, the busted microcode is still available on the Intel Download Center[1], without any warning that they recommend that you not, in fact, install it. Second, the press release is still being evasive: they have not merely "received reports"; they in fact know that it's causing issues, and the press release is avoiding the much stronger language that Intel is giving priv…

Why should they bother communicating clearly with their customers? Who are those customers going to turn to? AMD? ARM? Between Intel's numerous CPU bugs that they refused to refund customers for and ME, it's crystal clear what Intel thinks about their customers.

>Between Intel's numerous CPU bugs that they refused to refund customers for

How do you propose this could work?

Are side channel vulnerabilities in CPUs really bugs?

Re: Intel Security Issue Update: Addressing Reboot Issues

#39
post #37
post #16

Earlier quoted context omitted.

Why should they bother communicating clearly with their customers? Who are those customers going to turn to? AMD? ARM? Between Intel's numerous CPU bugs that they refused to refund customers for and ME, it's crystal clear what Intel thinks about their customers.

>Between Intel's numerous CPU bugs that they refused to refund customers for How do you propose this could work? Are side channel vulnerabilities in CPUs really bugs?

They promise modern process isolation and fail to deliver it. Their fixes reduce performance significantly. IANAL, but that sounds like a defective product.

Re: Intel Security Issue Update: Addressing Reboot Issues

#40
post #37
post #16

Earlier quoted context omitted.

Why should they bother communicating clearly with their customers? Who are those customers going to turn to? AMD? ARM? Between Intel's numerous CPU bugs that they refused to refund customers for and ME, it's crystal clear what Intel thinks about their customers.

>Between Intel's numerous CPU bugs that they refused to refund customers for How do you propose this could work? Are side channel vulnerabilities in CPUs really bugs?

I mean, this one, yea. Speculative execution should not have side effects when wrong because it is Intel silently, sneakily breaking the model of how the CPU works (at least, if you only include the cache in how the PC works and not branch prediction).

I would have expected, if I thought to ask, that items were not added to the cache or were removed from the cache if the branch was not retired.

Post reply on HN