Live data from Hacker News

OpenBSD was right to disable hyperthreading [video]

youtube.com

151–160 of 284 posts

Re: OpenBSD was right to disable hyperthreading [video]

#151
There was a longish recent thread on a mailing list where people described well (and linked to) why they like OpenBSD.

https://marc.info/?l=openbsd-misc&m=156700281107546&w=2

The most recent one I saw gave a reasonable sense of some tradeoffs:

https://marc.info/?l=openbsd-misc&m=156750048426578&w=2

I'm sure they welcome donations. :) Software they have written have benefited many, directly or indirectly (like OpenSSH).

...but the whole thread was interesting I thought.

Re: OpenBSD was right to disable hyperthreading [video]

#152

Earlier quoted context omitted.

Linux came after the BSDs, so you would think the BSDs would have won. There are many reasons Linux-based systems are generally much more popular than the BSDs in the server and workstation spaces. Here's why I think that happened: * GPL vs. BSD license. Repeatedly someone in the BSD community had the bright idea of creating a proprietary OS based on a BSD. All their work was then not shared with the OSS BSD communit…

GNU + Linux were far more decentralized (bazaar) That's the first time I've ever heard GNU associated with the bazaar. The original thesis of the book (CatB) is the observation that GNU is a cathedral (with saint rms at its head) and Linux (the kernel) is a bazaar.

I think the point is that it's all relative.

Re: OpenBSD was right to disable hyperthreading [video]

#153

I disable hyperthreading for better performance. In my experience as a mathematician building parallel compute servers, hyperthreading generates more heat than it is worth. I can overclock further without hyperthreading, to more than overtake the faint advantage that hyperthreading offers at a given clock speed. So I now buy binned, delidded processors from Silicon Lottery, choosing the best reasonably priced speed o…

The number of generations of processors where this has been true is really astounding to me. It really makes me wonder why they persist with this line of effort instead of doing something else, like cores that share logic units only.

Re: OpenBSD was right to disable hyperthreading [video]

#154
post #99

Earlier quoted context omitted.

This is why we need enormous fines for security breaches, and smaller fines just for not following best practices. Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance. Just like…

Not taking anything away from your point, I think we should also have real negative consequences for the people who commit security breaches. There is a real social stigma with regard to committing robbery, burglary, breaking and entering, etc. I feel like there isn't so much with online crime. As a community we really pile the blame on the victim for not be prepared and seem to give the perpetrators a pass for takin…

> It is a difficult tradeoff.

It's not a tradeoff we can make because the nature of computer security is that unless you fix the software and networks, you can't even identify the criminals, let alone catch them, presuming they're even in your legal jurisdiction. There's a tremendous asymmetry between attacker and defender in terms of cost+benefit, and it heavily favors the attacker.

In any event, computer crimes are punished with an iron fist in the U.S. What's not criminally prosecuted and punished very well is harassment. Yes, if social media platforms offered less anonymity, we could deal with harassment easier. But organized criminal organizations don't need the anonymity of Twitter to pilfer and fence credit card numbers; they have the anonymity of zombie networks and stolen accounts. And you can't address that with harsher penalties. If you penalized that activity with summary execution, the problem would substantially remain. And in fact in some respects it could get worse by deterring security research.

We have no choice but to fix the vulnerabilities. We have to make it more difficult to execute these attacks from a technical perspective, dramatically increasing the likelihood of identification and capture, before we can even hope of using criminal penalties as a substantial deterrent. We're a long way off from that day.

Re: OpenBSD was right to disable hyperthreading [video]

#156
post #2

Why aren’t the *BSD operating systems more popular in the server and workstation spaces?

Linux came after the BSDs, so you would think the BSDs would have won. There are many reasons Linux-based systems are generally much more popular than the BSDs in the server and workstation spaces. Here's why I think that happened: * GPL vs. BSD license. Repeatedly someone in the BSD community had the bright idea of creating a proprietary OS based on a BSD. All their work was then not shared with the OSS BSD communit…

Some claim that the AT&T lawsuit hurt the BSDs, but there was lawsuit-rattling for Linux and GNU as well

Do you mean the SCO lawsuit against IBM? Because I would argue that 1) that happened long enough after Linux had established itself that people were too invested to be immediately scared off and 2) people put a lot of faith in IBM and there legal team to defend Linux. I think the community around Linux was able to basically laugh the whole thing off once SCO started presenting their actual "evidence".

Without a large company to defend it and the fact that no one had really started using it for anything serious yet made the AT&T lawsuit against the BSD's look a lot scarier at the time.

All good points by the way, but I do think AT&T rattling their sword did have a pretty chilling effect on BSD adoption as well.

Re: OpenBSD was right to disable hyperthreading [video]

#157
post #127

Earlier quoted context omitted.

Lacking in charisma hardly describes a person like Theo de Raadt. I've never met the man, but I doubt that someone who lacks charisma could have lead a dedicated, opinionated team through more than 40 releases (counting OpenBSD releases alone!), over a period of almost 25 years now, a team which not only developed a sturdy (if equally opinionated) operating system but also a bunch of highly successful projects like,…

the same applies to Stallman, if you consider that the FSF has been running for 34 years. But I believe grandparent didn't mean they lack charisma, but that they didn't have enough to swerve the general public.

I would posit that:

    impact = charisma * funding
so .1 charisma score of some faceless tech exec * 1B in VC funding goes alot more than 2.0 charisma score * 50k of grasroots funding..

Re: OpenBSD was right to disable hyperthreading [video]

#158
post #155

Earlier quoted context omitted.

How is hyperthreading being insecure not a defect?

A new technique to pick locks is discovered. Does that mean all locks are defective?

When the Kaba Simplex (a commercial door lock) was discovered to be easily bypassed by holding a magnet near it, yes, it was in fact a design defect and the company had to correct it by giving repair kits out to purchasers.

Re: OpenBSD was right to disable hyperthreading [video]

#159
post #120
post #99

Earlier quoted context omitted.

This is why we need enormous fines for security breaches, and smaller fines just for not following best practices. Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance. Just like…

Don't know why you're comment is grayed, we absolutely need heavy monetary penalties for the worst kinds of data breaches. The abstract idea of a class action lawsuit isn't enough, even after the Equifax breach.

Do you have a similar opinion in regards to crimes? Do you think that there will be less crime if there are harsher prison sentences? Are you in favor of mandatory minimum sentences?

If not, why do you think harsher punishments are needed here but not for crimes?

Re: OpenBSD was right to disable hyperthreading [video]

#160
post #99

Earlier quoted context omitted.

Does that apply here? The BSD guys chose security over speed, as is their mantra, but companies that run linux for profit prioritize speed and cost per computing unit over security. I think 'disable hyperthreading' would be a difficult sell even for Steve Jobs.

This is why we need enormous fines for security breaches, and smaller fines just for not following best practices. Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance. Just like…

The problem with fines is that they happen after the fact and only if the worst actually happens. Tons of companies have totally abominable security and never get breached only out of dumb luck. So you'll still get lots of companies playing Russian Roulette where they make higher profits for ten years before they may or may not suffer a breach and get fined into oblivion, at which point they file for bankruptcy and start over.

You also end up creating a lot of really perverse incentives, like nefarious companies not disclosing data breaches because disclosing them would result in liability even though that's necessary for the victims to take steps to mitigate the damage. There's a reason the NTSB does no-fault investigations.

And a lot of mediocre but still harmful incentives like cargo culting decades-old security checklists to satisfy compliance requirements even though they don't actually result in improved security, but do create a false sense of security.

More than that, the problem is that humans are fallible, so even if you do 99.9% of everything right you can still make a mistake. A company with one security vulnerability can get just as compromised as a company with ten thousand. Does it really make sense to destroy OpenBSD with fines as soon as they have one security vulnerability? Or every random company that uses OpenSSH on a day that a not publicly known 0-day is being exploited in the wild? Or a company that updates to the latest version of some software that claims to have fixed a CVE even though it didn't?

The real problem here is architectural. It shouldn't be possible for someone to breach Equifax and get all your information because they shouldn't have that information to begin with. They shouldn't exist. Your data should be yours, on your device, so that it isn't possible for someone to get it by breaching a third party because the third party doesn't have it.

Post reply on HN