I can think of two theories: 1. It's a mistake. Someone in legal got carried away. 2. The performance of the L1TF mitigation is so awful that someone at Intel thought it would be a good idea to try to keep the performance secret. (Which leads to option 2b. The performance of the L1TF mitigation is so awful that somemone at Intel is afraid that Intel could be sued as a result, and they want to mitigate that risk.) I w…
Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
61–70 of 499 posts
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#62Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#63> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#64> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript
Have timing attacks been done successfully in JS? I imagine it's much harder since you have much less low-level control and the engine might impose too much noise. However, wasm is a different story.
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#65Sorry if I stress this even one more time, but we badly need 100% open iron, I mean something beefier than SiFive. If there is any effort in this direction, then, say for a year, most donations should be diverted over there. Closed hardware is becoming the unavoidable medium used to push closed firmware into everyone's system, that's a lot more important than benchmarks.
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#66> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript
"Many customers" meaning people and orgs running server software on direct hardware. Does your caching or database server run user provided code? Is it accessible to the outside in any way? If not, then maybe it doesn't need the patch.
lol, javascript
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#67Simple solution in comments: [ i7-8750H ] User1: do benchmark on no patch Os post in thread User2: do benchmark on patched OS, post in thread Is not a compare only performance graph between two users computer remember USER1 is patched
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#68> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript
Microsoft will surely decide for me on my Windows 10 gaming PC. Better save my work (which I sometimes do even on a gaming machine) frequently lest the masters deem it fit to restart while I'm away having lunch if they decide I can live with the performance hit.
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#69Bring on the lawsuits. Ignore the patches and sue Intel for the underlying security flaws. When they point to the patches, clearly state that because of the new license, they do not solve the problem and will not be applied. No one signed up for this when they bought an Intel CPU and that's saying a lot considering all the bullshit we do sign up for when buying one. This is outrageous. Intel should be sued in a class…
Which, of course, makes the kind of systematic deception Intel is trying to pull off here much easier. It's a feature!
Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed
#70Earlier quoted context omitted.
It wouldn't work. Even online media gets pretty strong first amendment protections that mean Intel wouldn't have a complete open and shut case, and we tech journalists are smart enough to be able to get the same microcode updates through other channels that don't have the same strings attached. If it's meant to deter anybody, it's the big corporate customers and competitors.
Unfortunately, the First Amendment does not protect against private action, only government restraints on speech. Other mechanisms like anti-SLAPP laws might help with that, but either way that's a lot of legal effort to publish some benchmarks. Intel also operates all over the world, so they could eg. sue a Britain-based branch of some media outlet that also publishes the numbers if the laws there are more in their…