Live data from Hacker News

OpenBSD was right to disable hyperthreading [video]

youtube.com

91–100 of 284 posts

Re: OpenBSD was right to disable hyperthreading [video]

#91
post #74

A wee bit offtopic, but if we look at the VW/dieselgate, and the aftermath of it all, and the class-actions, returns, refunds, etc, and hyundai/kia lies about gas milage and people getting refunds for gas... ...when is something like this going to happen to intel? We've bought CPUs with excpectations of promised performance (like people did with emission expectations and gas milage expectations), they messed up, and…

If I sell you a lock, and then 10 years later someone finds a vulnerability with the lock I sold you, should I refund you? That seems absurd. You are basically saying the product has to be perfect and the architects have to be able to see the future. Even if your hardware is formally verified, people can do physical attacks like listening to high frequency chirps of your cpu and using that to break security. Do you s…

Locks often offer a lifetime warranty against manufacturing defects in their locks.

Is this a manufacturing defect in CPUs?

(The defect is baked into hard silicon out in the world, so the analogy is plausible.)

Re: OpenBSD was right to disable hyperthreading [video]

#92
post #30
post #9

History will show that Theo was right in a manner similar to how Stalman was right: technically correct analysis and eerily accurate predictions, but lacking in sufficient charisma to create more than a small following. To some extent, you might say they are like Cassandra; speaking the truth but not believed or listened to.

Tannenbaum perhaps somewhere in the middle. Huge install base, but little noteriety.

Minix only has a "huge install base" because of Intel ME firmware junk.

Its not really meaningful, because the firmware could be pretty much any arbitrary OS and it would make zero difference to any end user.

Tannenbaum himself didnt even know about Intel using MINIX in their ME firmware until recently, so that should show you how much relevance it has.

Re: OpenBSD was right to disable hyperthreading [video]

#93
post #2

Why aren’t the *BSD operating systems more popular in the server and workstation spaces?

It is if you know where to look or who to talk to. That is the exact same question I was asked ~20 years ago regarding Linux vs Windows. The barrier to entry is higher on *BSD then it is on Linux. But with the appropriate skills/time/energy it is very much worth the effort. ALL of my edge devices run OpenBSD(since 2011). Most of my Internal servers run FreeBSD (90+%), with the remainder on OpenBSD. I made the decisio…

This is pretty much my experience, too, almost word-for-word. I also run OpenBSD on my edge nodes and FreeBSD for most app servers. After using FreeBSD on servers for about two years, I felt more comfortable with it than I do with Linux after 20 years. A large part of that is FreeBSD's simplicity, consistency, and documentation. It means I can pull on a thread and follow it myself, often without resorting to mailing lists. On Linux, I often feel like I'm trying to piece together information from a variety of sources, sometimes outdated or not applicable to the distro I'm running. BSD feels more cohesive to me, and I think that makes me more self-reliant.

Re: OpenBSD was right to disable hyperthreading [video]

#94
post #9

History will show that Theo was right in a manner similar to how Stalman was right: technically correct analysis and eerily accurate predictions, but lacking in sufficient charisma to create more than a small following. To some extent, you might say they are like Cassandra; speaking the truth but not believed or listened to.

"lacking in charisma" sort of implies that they have too little, but still some and doesn't really account for how they actively piss off other technologists and push them away, however right they may be technically.

Re: OpenBSD was right to disable hyperthreading [video]

#95
post #74

Earlier quoted context omitted.

If I sell you a lock, and then 10 years later someone finds a vulnerability with the lock I sold you, should I refund you? That seems absurd. You are basically saying the product has to be perfect and the architects have to be able to see the future. Even if your hardware is formally verified, people can do physical attacks like listening to high frequency chirps of your cpu and using that to break security. Do you s…

10 years? Of course not. But if i bought it yesterday, I'd expect a refund. Just consider that they were still selling affected CPUs even when they knew about the vulnerabilities and even after the papers were published.

They are still selling them today.

Re: OpenBSD was right to disable hyperthreading [video]

#96
post #74

A wee bit offtopic, but if we look at the VW/dieselgate, and the aftermath of it all, and the class-actions, returns, refunds, etc, and hyundai/kia lies about gas milage and people getting refunds for gas... ...when is something like this going to happen to intel? We've bought CPUs with excpectations of promised performance (like people did with emission expectations and gas milage expectations), they messed up, and…

If I sell you a lock, and then 10 years later someone finds a vulnerability with the lock I sold you, should I refund you? That seems absurd. You are basically saying the product has to be perfect and the architects have to be able to see the future. Even if your hardware is formally verified, people can do physical attacks like listening to high frequency chirps of your cpu and using that to break security. Do you s…

Indeed its the difference between lying and making a mistake. Off course they hoped with, plausible deniability, to mask those lies as mistakes: but they got caught. Hence the class action suits.

Re: OpenBSD was right to disable hyperthreading [video]

#97
post #74

Earlier quoted context omitted.

If I sell you a lock, and then 10 years later someone finds a vulnerability with the lock I sold you, should I refund you? That seems absurd. You are basically saying the product has to be perfect and the architects have to be able to see the future. Even if your hardware is formally verified, people can do physical attacks like listening to high frequency chirps of your cpu and using that to break security. Do you s…

Locks often offer a lifetime warranty against manufacturing defects in their locks. Is this a manufacturing defect in CPUs? (The defect is baked into hard silicon out in the world, so the analogy is plausible.)

It’s not a defect, so the analogy doesn’t work

Re: OpenBSD was right to disable hyperthreading [video]

#99
post #9

History will show that Theo was right in a manner similar to how Stalman was right: technically correct analysis and eerily accurate predictions, but lacking in sufficient charisma to create more than a small following. To some extent, you might say they are like Cassandra; speaking the truth but not believed or listened to.

Does that apply here? The BSD guys chose security over speed, as is their mantra, but companies that run linux for profit prioritize speed and cost per computing unit over security. I think 'disable hyperthreading' would be a difficult sell even for Steve Jobs.

This is why we need enormous fines for security breaches, and smaller fines just for not following best practices.

Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance.

Just like the majority of industries, we need real negative consequences for when we dump incompetent code out into the world. We've tried the "no consequences at all" plan for a long time and it's gotten us, well, continual data breaches via the easiest possible things to control. S3 buckets and databases open to the world. An inability to patch known CVEs in under 3 months (hi Equifax!).

Re: OpenBSD was right to disable hyperthreading [video]

#100
post #76

Earlier quoted context omitted.

Isn't this a "sane" default only in specific contexts though? (VMs). For a desktop PC that almost always runs a single heavy task (games, rendering, video encoding, etc) hyperthreading can be a day and night difference.

One must consider the potential damages that can happen when the default is wrong, as it’s nigh certain that people are going to be careless and not change it. If the desktop PC has wrong default the performance is bad. Still functional though. If in case of VM the default is wrong we will read another headline about how N million customers of $company got their personal data leaked.

I think we'll read such headlines regardless of that setting :-P.

I'm actually wondering if there should be some sort of premade "profiles" when it comes to default settings. Debian for example is used in a lot of contexts so perhaps it'd make sense to have a way to ask you what sort of usage you'll do when installing and provide different defaults based on that (not just at the initial installation time but also when installing some package, the default settings would be based on the profile you chose).

Post reply on HN