Live data from Hacker News

Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

perens.com

101–110 of 499 posts

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#101
post #2

I'm really curious how Intel could even imagine this is enforceable. For instance, if I have a server with shell access for many users, am I supposed to forbid my users from publishing benchmarks? If they do, am I liable since I "agreed" to the license? Or are they, even though they never "agreed" to the license? It just doesn't make sense.

Has anything even remotely similar to this ever been enforced anywhere? (Apart from the US)?

Once I have the application (or in this case, the microcode) it would seem the data I produce with it is mine to do as I please with? Otherwise it would be like microsoft saying that I couldn't publish any .docx files online that I produced with their software?

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#102
post #95

> Since some similar exploits have been discovered for AMD and ARM CPUs, the answer is probably “no”. But certainly customers are upset. Whats to be upset? Don't update if you are upset. Choose between perf/security. What are the options, anyway? You can be upset that the things are the way they are, however you can't blame Intel/AMD/ARM, etc. You should have been upset if these vulerabilities were known and not fixe…

People are upset because Intel is not allowing people to run benchmarks on their CPUs (the language is so vague that you could argue that running non-CPU benchmarks, or benchmarks for other software unrelated to Intel would violate this license). So you can't really make a "choice between performance/security", because nobody is allowed to publish data that would let you make an informed choice.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#103
post #13

I can think of two theories: 1. It's a mistake. Someone in legal got carried away. 2. The performance of the L1TF mitigation is so awful that someone at Intel thought it would be a good idea to try to keep the performance secret. (Which leads to option 2b. The performance of the L1TF mitigation is so awful that somemone at Intel is afraid that Intel could be sued as a result, and they want to mitigate that risk.) I w…

It works for Oracle (it is famously illegal to publish benchmarks of DB2 vs other engines), I'm sure intel can make it work for them thanks to Oracle's court case(s).

I believe you are referring to the DeWitt clause.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#104
Good thing we still have a somewhat anonymous internet. I'd be surprised if there wasn't a benchmark or two on the HN front page by tomorrow.

Might even come from a media organization if their lawyers deem this sufficiently unlikely to be enforcable in their country.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#105
post #52

> The security fixes are known to significantly slow down Intel processors, which won’t just disappoint customers and reduce the public regard of Intel, it will probably lead to lawsuits (if it hasn’t already). Suddenly having processors that are perhaps 5% to 10% slower, if they are to be secure, is a significant damage to many companies that run server farms or provide cloud services. Maybe I'm missing something he…

> Is the L1TF mitigation actually a lot worse than I thought, or does this license apply to the earlier Spectre/Meltdown patches, or is Bruce Perens just being sloppy and conflating the two?

He isn't being sloppy. According to the Debian package maintainer[1], the new license only applies to the new patches (ones after 2018-08-07) which were released long after the Spectre/Meltdown ones -- because the license was only changed in the 20180807 microcode update (and because Debian didn't block the previous Spectre/Meltdown releases over license concerns).

In theory, nobody can actually tell you how bad the L1TF mitigation is because of the new license terms (a comparison before-and-after L1TF mitigation would be providing you with comparison test results).

[1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906158#14

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#108
post #35

Bring on the lawsuits. Ignore the patches and sue Intel for the underlying security flaws. When they point to the patches, clearly state that because of the new license, they do not solve the problem and will not be applied. No one signed up for this when they bought an Intel CPU and that's saying a lot considering all the bullshit we do sign up for when buying one. This is outrageous. Intel should be sued in a class…

How many mandatory binding arbitration clauses and/or class action waivers have Intel hidden in their license agreements over the years? If they did it right, they never have to worry about a class action lawsuit (and the horrible press that comes with it) anytime soon. Which, of course, makes the kind of systematic deception Intel is trying to pull off here much easier. It's a feature!

I could be wrong but I think binding arbitration is almost exclusively an American thing. The rest of the world can sue.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#109
post #35

Bring on the lawsuits. Ignore the patches and sue Intel for the underlying security flaws. When they point to the patches, clearly state that because of the new license, they do not solve the problem and will not be applied. No one signed up for this when they bought an Intel CPU and that's saying a lot considering all the bullshit we do sign up for when buying one. This is outrageous. Intel should be sued in a class…

How many mandatory binding arbitration clauses and/or class action waivers have Intel hidden in their license agreements over the years? If they did it right, they never have to worry about a class action lawsuit (and the horrible press that comes with it) anytime soon. Which, of course, makes the kind of systematic deception Intel is trying to pull off here much easier. It's a feature!

I wasn't aware that CPUs have licenses. It's certainly not something I've ever agreed to on purpose or otherwise. There is no box or manual to imply that I have ever agreed to such a license. I'm not doubting you, I'm just wondering where this license lies and when/how did I agree to it?

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#110

Aside from my vic20 and c64 I’ve only ever owned intel CPUs, and those two may have been intel as well, I wouldn’t know. I’ve never made a decision to chose Intel based on benchmark, I’ve bought them because they’ve always been great for me. So it’ll be ironic when I buy an AMD processor when I upgrade for cyberpunk 2077, because of benchmarks. Not because AMD is faster, they may be but I wouldn’t know, no, it’ll be…

Of course, this license is a virtual benchmark: Intel spares you the work of running tests with their implicit claim that their performance is worse than anyone's lowest expectations.
Post reply on HN