Live data from Hacker News

Intel Security Issue Update: Addressing Reboot Issues

newsroom.intel.com

61–70 of 129 posts

Re: Intel Security Issue Update: Addressing Reboot Issues

#61
post #16

Earlier quoted context omitted.

Why should they bother communicating clearly with their customers? Who are those customers going to turn to? AMD? ARM? Between Intel's numerous CPU bugs that they refused to refund customers for and ME, it's crystal clear what Intel thinks about their customers.

There are issues with this 'laptop' (don't put it on your lap is one), but AMD is a viable option I think.. https://imgur.com/Qsodtxv

> There are issues with this 'laptop' (don't put it on your lap is one)

ouch, that is definitiv not a good issue... but well my mbp late 2013" gets hot as well.

Re: Intel Security Issue Update: Addressing Reboot Issues

#62

“We have received reports from a few customers of higher system reboots after applying firmware updates.” What does higher mean here?

The original statement, as phrased by their engineers, probably was something like “Our latest firmware regularly crashes your system, triggering reboots” (plus a few paragraphs with a highly detailed description of why that happened that only the engineers who wrote the firmware would understand)

This is what they ended up with after a few reviews with legal (“we can’t say ‘our’; they’ll eat us in court”) and marketing (“We need a less emotionally loaded way to say ‘crash’”)

Legal aimed to maintain just enough meaning in the statement to be able to say “we warned customers as soon as we could”; marketing aimed to make it a positive message. I guess that’s why ‘higher’ won over ‘more’.

Re: Intel Security Issue Update: Addressing Reboot Issues

#63
post #40
post #37

Earlier quoted context omitted.

>Between Intel's numerous CPU bugs that they refused to refund customers for How do you propose this could work? Are side channel vulnerabilities in CPUs really bugs?

I mean, this one, yea. Speculative execution should not have side effects when wrong because it is Intel silently, sneakily breaking the model of how the CPU works (at least, if you only include the cache in how the PC works and not branch prediction). I would have expected, if I thought to ask, that items were not added to the cache or were removed from the cache if the branch was not retired.

Removing items afterwords probably wouldn't work as you might be able stuff (instead of flush) the cache and figure out which line was emptied.

Intel isn't being sneaky, speculative reading was a standard and accepted feature for out of order processors for over 20 years (remember it affects ARM,AMD,Apple,IBM etc as well). Speculative reading privileged memory while unprivileged was a big mistake though.

Re: Intel Security Issue Update: Addressing Reboot Issues

#64
post #13

I think it's a bit ironic that the text, in a sense, blames Google for these problems by calling them the "Google Project Zero Exploits" as if Google was some sort of cyber crime syndicate using their evil powers to exploit intel.

I rather read it as giving them credit.

Re: Intel Security Issue Update: Addressing Reboot Issues

#65
post #20
post #6

Earlier quoted context omitted.

if you're going to make the accusation that they're lying, at least provide a source - near as I can tell they are being as transparent as is reasonable.

bcantrill is https://en.wikipedia.org/wiki/Bryan_Cantrill If he is saying that Intel is giving other advice privately then you are welcome not to believe him (and note that it is you who is using the much stronger term "lying" here). Personally I think un-sourced statements from him are worth listening to.

My general attitude is to presume good faith - both on intels part, and on the part of commenters online. I had no idea who he was till you raised the point with me - had he I identified some source for his assertions (even first had observation on a large number of systems), I probably wouldn't have said anything.

Re: Intel Security Issue Update: Addressing Reboot Issues

#66
post #40

Earlier quoted context omitted.

I mean, this one, yea. Speculative execution should not have side effects when wrong because it is Intel silently, sneakily breaking the model of how the CPU works (at least, if you only include the cache in how the PC works and not branch prediction). I would have expected, if I thought to ask, that items were not added to the cache or were removed from the cache if the branch was not retired.

Removing items afterwords probably wouldn't work as you might be able stuff (instead of flush) the cache and figure out which line was emptied. Intel isn't being sneaky, speculative reading was a standard and accepted feature for out of order processors for over 20 years (remember it affects ARM,AMD,Apple,IBM etc as well). Speculative reading privileged memory while unprivileged was a big mistake though.

Intel's greatest PR success in this mess has been to conflate Meltdown with Spectre. Only Intel is affected by Meltdown because of their design, and it is a more easily exploited bug.

Re: Intel Security Issue Update: Addressing Reboot Issues

#68
post #61

Earlier quoted context omitted.

There are issues with this 'laptop' (don't put it on your lap is one), but AMD is a viable option I think.. https://imgur.com/Qsodtxv

> There are issues with this 'laptop' (don't put it on your lap is one) ouch, that is definitiv not a good issue... but well my mbp late 2013" gets hot as well.

Have you tried cleaning the dust accumulated inside?

Re: Intel Security Issue Update: Addressing Reboot Issues

#69

This is -- to say the least -- frustrating. First, the busted microcode is still available on the Intel Download Center[1], without any warning that they recommend that you not, in fact, install it. Second, the press release is still being evasive: they have not merely "received reports"; they in fact know that it's causing issues, and the press release is avoiding the much stronger language that Intel is giving priv…

[deleted]

Re: Intel Security Issue Update: Addressing Reboot Issues

#70
post #66

Earlier quoted context omitted.

Removing items afterwords probably wouldn't work as you might be able stuff (instead of flush) the cache and figure out which line was emptied. Intel isn't being sneaky, speculative reading was a standard and accepted feature for out of order processors for over 20 years (remember it affects ARM,AMD,Apple,IBM etc as well). Speculative reading privileged memory while unprivileged was a big mistake though.

Intel's greatest PR success in this mess has been to conflate Meltdown with Spectre. Only Intel is affected by Meltdown because of their design, and it is a more easily exploited bug.

Meltdown is not only Intel. Some ARM and Apple designed ARM processors are affected by Meltdown as well. https://en.wikipedia.org/wiki/Meltdown_(security_vulnerabili...
Post reply on HN