Live data from Hacker News

Intel Security Issue Update: Addressing Reboot Issues

newsroom.intel.com

81–90 of 129 posts

Re: Intel Security Issue Update: Addressing Reboot Issues

#81
post #66

Earlier quoted context omitted.

Removing items afterwords probably wouldn't work as you might be able stuff (instead of flush) the cache and figure out which line was emptied. Intel isn't being sneaky, speculative reading was a standard and accepted feature for out of order processors for over 20 years (remember it affects ARM,AMD,Apple,IBM etc as well). Speculative reading privileged memory while unprivileged was a big mistake though.

Intel's greatest PR success in this mess has been to conflate Meltdown with Spectre. Only Intel is affected by Meltdown because of their design, and it is a more easily exploited bug.

Meltdown is a Variant of Spectre this isn't how Intel classifies it, this is how Google Project Zero, and heck even Intel's competitor AMD classifies it.

https://www.amd.com/en/corporate/speculative-execution

https://googleprojectzero.blogspot.co.uk/2018/01/reading-pri...

It's also not the scariest variant, it's easily fixed (performance degradation aside), doesn't require a microcode update to be fixed hence is 100% software mitigated, doesn't allow you to cross between guest and host memory address spaces and isn't remotely exploitable.

On the other hand variant 1 and 2 are much scarier because they are the complete opposite of Meltdown.

Re: Intel Security Issue Update: Addressing Reboot Issues

#82
post #16

Earlier quoted context omitted.

Why should they bother communicating clearly with their customers? Who are those customers going to turn to? AMD? ARM? Between Intel's numerous CPU bugs that they refused to refund customers for and ME, it's crystal clear what Intel thinks about their customers.

There are issues with this 'laptop' (don't put it on your lap is one), but AMD is a viable option I think.. https://imgur.com/Qsodtxv

Well AMD mobile CPUs are 4 core, so I would assume you bought one of the hackjob DTR's with a desktop CPU or just are using a desktop in a jest :P

Re: Intel Security Issue Update: Addressing Reboot Issues

#83
post #48
post #31

Earlier quoted context omitted.

With the implication that random reboots of a lesser, but non-zero frequency are okay, it's at least expected? Odd wording for sure.

If you have Intel wireless or display drivers installed then it is perfectly normal for a computer to randomly reboot.

How often?

I have 495 days of uptime here with intel graphics & wireless.

Re: Intel Security Issue Update: Addressing Reboot Issues

#84
post #13

I think it's a bit ironic that the text, in a sense, blames Google for these problems by calling them the "Google Project Zero Exploits" as if Google was some sort of cyber crime syndicate using their evil powers to exploit intel.

Wow, that's a good point. "...the exploits uncovered by Google Project Zero" would be much, much more appropriate.

[deleted]

Re: Intel Security Issue Update: Addressing Reboot Issues

#85
post #83
post #48

Earlier quoted context omitted.

If you have Intel wireless or display drivers installed then it is perfectly normal for a computer to randomly reboot.

How often? I have 495 days of uptime here with intel graphics & wireless.

Reboot your PC mate, the kernel needs updating.

Re: Intel Security Issue Update: Addressing Reboot Issues

#89
post #66

Earlier quoted context omitted.

Intel's greatest PR success in this mess has been to conflate Meltdown with Spectre. Only Intel is affected by Meltdown because of their design, and it is a more easily exploited bug.

Meltdown is a Variant of Spectre this isn't how Intel classifies it, this is how Google Project Zero, and heck even Intel's competitor AMD classifies it. https://www.amd.com/en/corporate/speculative-execution https://googleprojectzero.blogspot.co.uk/2018/01/reading-pri... It's also not the scariest variant, it's easily fixed (performance degradation aside), doesn't require a microcode update to be fixed hence is 100%…

Meltdown is not a variant of Spectre. Spectre itself has two variants.

And Meltdown was the easiest to exploit. Spectre is "bad" because it affects everyone, but it's less exploitable than Intel's Meltdown.

Re: Intel Security Issue Update: Addressing Reboot Issues

#90

Earlier quoted context omitted.

Customers actually could turn to AMD... their offerings are very competitive right now.

I'm thinking of building an AMD dev box. For enterprise consumers, if they're using 1U or blade servers, they could make the choice to switch to AMD for future nodes.

I have a Ryzen developer box at work and it is awesome, paired with 32GB of RAM and SSD's it absolutely screams.

My next home PC will be Ryzen 2 at some point this year.

Post reply on HN