Live data from Hacker News

Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

perens.com

61–70 of 499 posts

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#61
post #13

I can think of two theories: 1. It's a mistake. Someone in legal got carried away. 2. The performance of the L1TF mitigation is so awful that someone at Intel thought it would be a good idea to try to keep the performance secret. (Which leads to option 2b. The performance of the L1TF mitigation is so awful that somemone at Intel is afraid that Intel could be sued as a result, and they want to mitigate that risk.) I w…

It works for Oracle (it is famously illegal to publish benchmarks of DB2 vs other engines), I'm sure intel can make it work for them thanks to Oracle's court case(s).

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#63

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

Have timing attacks been done successfully in JS? I imagine it's much harder since you have much less low-level control and the engine might impose too much noise. However, wasm is a different story.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#64

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

Have timing attacks been done successfully in JS? I imagine it's much harder since you have much less low-level control and the engine might impose too much noise. However, wasm is a different story.

web search "spy in the sandbox"

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#65

Sorry if I stress this even one more time, but we badly need 100% open iron, I mean something beefier than SiFive. If there is any effort in this direction, then, say for a year, most donations should be diverted over there. Closed hardware is becoming the unavoidable medium used to push closed firmware into everyone's system, that's a lot more important than benchmarks.

Have you seen https://www.raptorcs.com/TALOSII/? Typing this on my own right now.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#66
post #54

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

"Many customers" meaning people and orgs running server software on direct hardware. Does your caching or database server run user provided code? Is it accessible to the outside in any way? If not, then maybe it doesn't need the patch.

The article says "Many computer users" not "Many customers". Furthermore when the article mentions "customers" elsewhere we can probably assume it means "Intel customers" which is a much greater subset than the group you're talking about, and which would be probably less than 1% as numerous as the "Many computer users" that run javascript.

lol, javascript

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#67

Simple solution in comments: [ i7-8750H ] User1: do benchmark on no patch Os post in thread User2: do benchmark on patched OS, post in thread Is not a compare only performance graph between two users computer remember USER1 is patched

you would have to demonstrate that the config from user1 is identical to the configuration of user2, wich mean you would have to split the patch up to the microde update.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#68

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

>Another issue is whether the customer should install the fix at all

Microsoft will surely decide for me on my Windows 10 gaming PC. Better save my work (which I sometimes do even on a gaming machine) frequently lest the masters deem it fit to restart while I'm away having lunch if they decide I can live with the performance hit.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#69
post #35

Bring on the lawsuits. Ignore the patches and sue Intel for the underlying security flaws. When they point to the patches, clearly state that because of the new license, they do not solve the problem and will not be applied. No one signed up for this when they bought an Intel CPU and that's saying a lot considering all the bullshit we do sign up for when buying one. This is outrageous. Intel should be sued in a class…

How many mandatory binding arbitration clauses and/or class action waivers have Intel hidden in their license agreements over the years? If they did it right, they never have to worry about a class action lawsuit (and the horrible press that comes with it) anytime soon.

Which, of course, makes the kind of systematic deception Intel is trying to pull off here much easier. It's a feature!

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#70
post #49
post #24

Earlier quoted context omitted.

It wouldn't work. Even online media gets pretty strong first amendment protections that mean Intel wouldn't have a complete open and shut case, and we tech journalists are smart enough to be able to get the same microcode updates through other channels that don't have the same strings attached. If it's meant to deter anybody, it's the big corporate customers and competitors.

Unfortunately, the First Amendment does not protect against private action, only government restraints on speech. Other mechanisms like anti-SLAPP laws might help with that, but either way that's a lot of legal effort to publish some benchmarks. Intel also operates all over the world, so they could eg. sue a Britain-based branch of some media outlet that also publishes the numbers if the laws there are more in their…

The First Amemdment itself doesn't directly apply to Intel, but there are a lot of relevant legal protections pertaining to the general idea of protecting the press. In particular, this seems to be fundamentally a copyright license that's at issue. News reporting, scholarship and research are all explicitly listed as purposes that can qualify as fair use. Using copyrighted material to research and report on the nature of defective goods being sold to the public strikes me as pretty likely to be ruled as fair use, especially when using the copyrighted microcode in a manner contrary to Intel's license is necessary to properly fact-check a news story about their processor flaws.
Post reply on HN