Live data from Hacker News

OpenBSD was right to disable hyperthreading [video]

youtube.com

131–140 of 284 posts

Re: OpenBSD was right to disable hyperthreading [video]

#131
post #99

Earlier quoted context omitted.

Does that apply here? The BSD guys chose security over speed, as is their mantra, but companies that run linux for profit prioritize speed and cost per computing unit over security. I think 'disable hyperthreading' would be a difficult sell even for Steve Jobs.

This is why we need enormous fines for security breaches, and smaller fines just for not following best practices. Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance. Just like…

What ever incentive you create and analogy you make. The hardware / software / internet has no parrellel. I’ve been thinking about the place of software in the context of other disciplines and here is the thing. If you are thrown back to the prehistory with 50 man dream team of engineers, and are told to recreate ... something. Let’s say the train station I was just in. A rudimentary train network could be created in maybe 50 years? ( starting with, how to make steel. ) Wat ever estimate you have, the work required before they recreate the lcd screens showing the time of arrival is easily double that.

With that as a barrier to entry , the only solution I could see working for security is: public domain hardware and software.

The only solution I believe

Re: OpenBSD was right to disable hyperthreading [video]

#132
post #2

Why aren’t the *BSD operating systems more popular in the server and workstation spaces?

In the early 1990s there was some legal dispute over the BSD license.

It spread FUD and prevented people from developing on BSD, and steered them towards Linux.

This is from memory, maybe someone else can fill in the details.

Re: OpenBSD was right to disable hyperthreading [video]

#133
post #99

Earlier quoted context omitted.

Does that apply here? The BSD guys chose security over speed, as is their mantra, but companies that run linux for profit prioritize speed and cost per computing unit over security. I think 'disable hyperthreading' would be a difficult sell even for Steve Jobs.

This is why we need enormous fines for security breaches, and smaller fines just for not following best practices. Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance. Just like…

Isn't GDPR supposed to be an attempt at this kind of thing, treating privacy issues as a punishable negative externality similar to pollution?

I only ask because that all makes perfect sense to me, but I see a lot of negativity about GDPR on here, that all it ever does is stifle innovation and produce ever more cookie-agreement popups.

Re: OpenBSD was right to disable hyperthreading [video]

#134

A wee bit offtopic, but if we look at the VW/dieselgate, and the aftermath of it all, and the class-actions, returns, refunds, etc, and hyundai/kia lies about gas milage and people getting refunds for gas... ...when is something like this going to happen to intel? We've bought CPUs with excpectations of promised performance (like people did with emission expectations and gas milage expectations), they messed up, and…

Even if you think any broken promise amounts to fraud, Intel didn't intentionally commit fraud.

Re: OpenBSD was right to disable hyperthreading [video]

#135
post #2

Why aren’t the *BSD operating systems more popular in the server and workstation spaces?

Linux came after the BSDs, so you would think the BSDs would have won. There are many reasons Linux-based systems are generally much more popular than the BSDs in the server and workstation spaces. Here's why I think that happened: * GPL vs. BSD license. Repeatedly someone in the BSD community had the bright idea of creating a proprietary OS based on a BSD. All their work was then not shared with the OSS BSD communit…

[deleted]

Re: OpenBSD was right to disable hyperthreading [video]

#136
post #120
post #99

Earlier quoted context omitted.

This is why we need enormous fines for security breaches, and smaller fines just for not following best practices. Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance. Just like…

Don't know why you're comment is grayed, we absolutely need heavy monetary penalties for the worst kinds of data breaches. The abstract idea of a class action lawsuit isn't enough, even after the Equifax breach.

Is there anything about how breaches are currently remediated that might contribute to better outcomes than if we adopted a higher and harsher penalty system?

It seems like it might create some perverse incentives as the risk escalates.

Re: OpenBSD was right to disable hyperthreading [video]

#137

Two of the three (current) top-level replies compare BSDs to Linux in general, but that really has nothing to do with whether you disable HT. Using Linux should not have stopped anyone from listening to Theo and disabling HT months ago. Your security authorities don't have to be your kernel developers.

How many other decisions made by kernel developers are you supposed to second-guess because you know better?

Re: OpenBSD was right to disable hyperthreading [video]

#138
Would it be that difficult to run chips in a secure mode with no hyperthreading or branch prediction when handling sensitive information and then takes the brakes off for normal operation? I mean, I wouldn't really care if someone was watching everything I do for 95% of my computer use time.

Re: OpenBSD was right to disable hyperthreading [video]

#139
post #73

Earlier quoted context omitted.

The BSDs aren't really much better in that regard once you leave the base install, and their hardware support is substantially worse.

I will agree hardware still lags but for the target of servers and serving its fine. As far as BSD being a mess after base I completely disagree. Using and understanding a package manager makes life pretty simple. That said if the Linux community did that they would probably realize how silly containers are :)

Linux uses a bunch of package managers, it doesn't solve anything yet creates the problem of "X isn't in the repo, now what?".

Re: OpenBSD was right to disable hyperthreading [video]

#140
post #97

Earlier quoted context omitted.

Locks often offer a lifetime warranty against manufacturing defects in their locks. Is this a manufacturing defect in CPUs? (The defect is baked into hard silicon out in the world, so the analogy is plausible.)

It’s not a defect, so the analogy doesn’t work

How is hyperthreading being insecure not a defect?
Post reply on HN