Live data from Hacker News

Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

perens.com

71–80 of 499 posts

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#71
post #24

Earlier quoted context omitted.

Surely it's just designed to scare the big media websites from publishing numbers.

It wouldn't work. Even online media gets pretty strong first amendment protections that mean Intel wouldn't have a complete open and shut case, and we tech journalists are smart enough to be able to get the same microcode updates through other channels that don't have the same strings attached. If it's meant to deter anybody, it's the big corporate customers and competitors.

Online media often relies on hardware directly from the manufacture when they get to test it before official release.

Nothing stops Intel from not sending them anything anymore, and then they have to buy it from the stores like everybody else.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#72

As a side note: Some of the license changes also block Debian from updating their intel-microcode package[1]. [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906158#14

This seems like it would be a big deal considering this whole thing is related to servers and I have to imagine some server operators are running Debian? Maybe at the bare metal level their all running RHEL, which I presume doesn't care about the license restrictions.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#73
post #8
post #2

I'm really curious how Intel could even imagine this is enforceable. For instance, if I have a server with shell access for many users, am I supposed to forbid my users from publishing benchmarks? If they do, am I liable since I "agreed" to the license? Or are they, even though they never "agreed" to the license? It just doesn't make sense.

Well the license specifically says you will not permit a third party to either. I don't really speak legalese, but does permit include having to then make all of your own users agree not to to avoid a penalty? As mentioned in the other comment thread though, I imagine the reality of this clause is to prevent media outlets (such as Phoronix who would traditionally do exactly this kind of benchmarking) from downloading…

> Well the license specifically says you will not permit a third party to either.

That might as well read as "you can't provide cloud computing" since you can't know what someone is going to execute on their server before they execute it!

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#74
post #13

I can think of two theories: 1. It's a mistake. Someone in legal got carried away. 2. The performance of the L1TF mitigation is so awful that someone at Intel thought it would be a good idea to try to keep the performance secret. (Which leads to option 2b. The performance of the L1TF mitigation is so awful that somemone at Intel is afraid that Intel could be sued as a result, and they want to mitigate that risk.) I w…

It works for Oracle (it is famously illegal to publish benchmarks of DB2 vs other engines), I'm sure intel can make it work for them thanks to Oracle's court case(s).

I'm pretty sure DB2 is an IBM thing.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#75

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

Have timing attacks been done successfully in JS? I imagine it's much harder since you have much less low-level control and the engine might impose too much noise. However, wasm is a different story.

Yes, Someone did an ASLR bypass in JavaScript, and a key component was being able to measure time accurately.

https://www.cs.vu.nl/~herbertb/download/papers/anc_ndss17.pd...

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#77
2018 has been an abysmal year for Intel so far. Multiple serious vulnerabilities that effect multiple areas of their products, Spectre, Meltdown, Management Engine, etc. The only thing they can control is how they respond and they've done a terrible job of that too. At this rate I'm expecting a consumer product agency to eventually get involved.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#78
post #24

Earlier quoted context omitted.

It wouldn't work. Even online media gets pretty strong first amendment protections that mean Intel wouldn't have a complete open and shut case, and we tech journalists are smart enough to be able to get the same microcode updates through other channels that don't have the same strings attached. If it's meant to deter anybody, it's the big corporate customers and competitors.

Online media often relies on hardware directly from the manufacture when they get to test it before official release. Nothing stops Intel from not sending them anything anymore, and then they have to buy it from the stores like everybody else.

I'm well aware of the theoretical possibility of Intel blacklisting publications. In practice, it only works against smaller publications and would backfire spectacularly if they tried it against the larger publications. Intel has more to lose than any one tech publication.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#79
post #8

Earlier quoted context omitted.

Well the license specifically says you will not permit a third party to either. I don't really speak legalese, but does permit include having to then make all of your own users agree not to to avoid a penalty? As mentioned in the other comment thread though, I imagine the reality of this clause is to prevent media outlets (such as Phoronix who would traditionally do exactly this kind of benchmarking) from downloading…

> Well the license specifically says you will not permit a third party to either. That might as well read as "you can't provide cloud computing" since you can't know what someone is going to execute on their server before they execute it!

And nobody releases production code to a cloud environment without performance testing of significant changes.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#80

Before Zen, we all kind of assumed they were so far ahead that AMD were more likely to be out of business before they would ever be a credible threat again. I actually thought Intel must have had some tricks up their sleeves in terms of performance gains that we hadn't seen yet, simply because there was no market need to roll them out and they had so many years of coasting on marginal gains. Seeing them taking this s…

>they've nothing significant to show for all that time and money spent when they were raking it in without a serious competitor.

Big companies rarely innovate without competition around.

Post reply on HN