Earlier quoted context omitted.
Your desktop PC is regularly running largely unverified code, some of it potentially hostile: all the javascript in your browser.
Browsers have mitigations in place, don't they? Aren't they enough, at least on paper?
OpenBSD was right to disable hyperthreading [video]
241–250 of 284 posts
Re: OpenBSD was right to disable hyperthreading [video]
#242Full interview: https://www.youtube.com/watch?v=sDrRvrh16ws One of the things the Linux kernel developer says in the interview is that researchers are going through Intel patents to find "security bugs". He says this is "fun". Twice. He seems pretty nonchalant about these issues. Like it is great to fix them, but not like it is too important or anything to worry about. He says what is most important to him is that Li…
Re: OpenBSD was right to disable hyperthreading [video]
#243Earlier quoted context omitted.
How so? I had to look Tiresias up on Wikipedia, a blind prophet, but I still don't see the connection. Would it be possible for you to please explain?
Tiresas' prophecies come true because of a poetic or literary recursion built into the Oedipus cycle or the Oresteia or whatever. (I'm AFK, where K means "my library.") So when the guy to whom Tiresias prophecies that said guy will commit patricide in fact kills his father, he does so because he tried to not kill his father, and in attempting to escape his destiny, inflicted it upon himself. Stallman's apocalyptic ra…
1. Cassandra is usually at the center of attention, an object of desire to Agamemnon and his troops, an object of hatred and jealousy to Clytemnestra and Aegisthus. Tiresias isn't nearly as ostentatious, and mostly exists passively in the background, waiting until someone else asks his opinion on something. Tiresias gives off a kind of awkward vibe, much like Stallman, compared to Cassandra, who's totally a social butterfly.
2. Cassandra is cool and sexy, Tiresias is a blind old dude. Richard Stallman eats stuff off his foot and often looks like he hasn't showered since the last emacs release.
3. Cassandra's prophecies are very straightforward, Agamemnon and his buddies understand what she says and even listen to her to some degree, they just don't care enough to do anything. Tiresias is much more cryptic and is always derided until the denouement when it is revealed that he was right all along, just in a way that nobody else could have foreseen. Likewise, Stallman's insights into the future of our technological dystopia seem absurd and maniacal until they inevitably come true a few years later.
I like your comment though =)
Re: OpenBSD was right to disable hyperthreading [video]
#244Earlier quoted context omitted.
Woah thanks. Dunno why someone downvoted this lol
I'm not sure, but commenting on downvoting is likely to attract downvotes as it's explicitly against the guidelines. https://news.ycombinator.com/newsguidelines.html
Re: OpenBSD was right to disable hyperthreading [video]
#245Earlier quoted context omitted.
Its not like that. Intel took shortcuts to make their CPUs faster. At least some of the chip architects working on their implementation of hyperthreading should have understood that they sacrificed security for speed - without telling anyone.
> should have understood that they sacrificed security for speed And what if they didn't? It's pretty much exactly like that. Intel has been making CPUs for well over a decade that are vulnerable to various side channel attacks, and the only thing that has changed is the community's understanding of the vulnerabilities (i.e. there's a new way to pick the lock).
Hyperthreading/SMT is a trickier issue because it had obvious and even proven side-channel potential from the beginning. But 1) everybody had to hold their nose in order to compete with Intel on SMT performance, and 2) technically the operating system communities should have made the effort to keep unrelated processes from sharing an SMT'd core. And that still needs to happen--we need smarter schedulers.
Re: OpenBSD was right to disable hyperthreading [video]
#246Why aren’t the *BSD operating systems more popular in the server and workstation spaces?
Linux just had "more stuff". Without any other particular reason to pick one over the other, most people picked the one with "more stuff". Nobody wanted to install an OS for a server just to find out it couldn't run the latest software, or didn't have the latest drivers. In addition, the userland of the BSDs was different from GNU tools; if you were already installing GNU tools on every other OS you adminned, you might as well run the OS that's based on it. Finally, if you wanted Enterprise support, Linux was the only Open Source choice, afaik.
Some at the timed claimed performance benefits from one or the other, but various benchmarks showed Linux and BSDs each had their respective performance strengths that could generally be overcome by tweaking.
Re: OpenBSD was right to disable hyperthreading [video]
#247Earlier quoted context omitted.
This is why we need enormous fines for security breaches, and smaller fines just for not following best practices. Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance. Just like…
In all honesty, security is just really hard and we're really bad at it. Perhaps an alternative would be to establish standards when it comes to security team headcount and salary in an organization? That way they're incentivized to follow the rules and you have more leeway to punish them if they don't follow the baseline.
Imagine if any other field said that. "Not burning people's houses down with electrical wiring is just really hard and we're really bad at it." "Keeping bridges standing is just really hard and we're really bad at it." "Flying across the country without killing any passengers is just really hard and we're really bad at it."
Re: OpenBSD was right to disable hyperthreading [video]
#248Earlier quoted context omitted.
Not taking anything away from your point, I think we should also have real negative consequences for the people who commit security breaches. There is a real social stigma with regard to committing robbery, burglary, breaking and entering, etc. I feel like there isn't so much with online crime. As a community we really pile the blame on the victim for not be prepared and seem to give the perpetrators a pass for takin…
> It is a difficult tradeoff. It's not a tradeoff we can make because the nature of computer security is that unless you fix the software and networks, you can't even identify the criminals, let alone catch them, presuming they're even in your legal jurisdiction. There's a tremendous asymmetry between attacker and defender in terms of cost+benefit, and it heavily favors the attacker. In any event, computer crimes are…
Re: OpenBSD was right to disable hyperthreading [video]
#249Earlier quoted context omitted.
I'm a right-wing libertarian, and I've never felt excluded or anything like that because of his leftist views. This for many reasons: 1) He's not a hypocrite in any way. He's honest and you can tell that he has truly thought about his opinions. 2) In my country, I get bombarded with a ralentless stream of leftist ideology. The worst kind of leftism: the lazy 'slogan' leftism, from people too stupid to realize the ful…
I don’t care about his views on those kind of politics at all. But when it comes to free software he is an ideological maximalist. Take a look at how he uses computers personally, his values (at least currently) don’t fit in with most users expectations of what personal computing should be. His contributions aren’t in question, and his voice is a valuable one to have in the choir, but he’s not a person willing to acc…
You need somebody as guideposts to stand at the extreme ends. I am glad RMS stands at his end.
Re: OpenBSD was right to disable hyperthreading [video]
#250Earlier quoted context omitted.
> should have understood that they sacrificed security for speed And what if they didn't? It's pretty much exactly like that. Intel has been making CPUs for well over a decade that are vulnerable to various side channel attacks, and the only thing that has changed is the community's understanding of the vulnerabilities (i.e. there's a new way to pick the lock).
It strains credulity to believe that Intel wasn't aware that they were trading side-channel resistance for performance. The problems are just too deep and pervasive. None of AMD, ARM, Power, or SPARC came close to the number and severity of issues in Intel chips. There were problems in those chips, but their nature and limited scope shows that everybody had a rough idea about how far they could go before they made pr…
I don't agree.
Meltdown: Intel, IBM, some ARM
Spectre v1: Intel, ARM, IBM
Spectre v2: Intel, ARM, IBM, AMD
Spectre v3a: Intel, ARM
Spectre v4: Intel, ARM, IBM, AMD
L1TF: Intel, IBM
Meltdown-PK: Intel
Spectre-PHT: Intel, ARM, AMD
Meltdown-BND: Intel, AMD
MDS: Intel
RIDL: Intel
That doesn't look to me like "everybody had a rough idea about how far they could go."
It is really easy for me to believe that a ton of designers could add optimizations without consideration of side channels. Nobody appreciated the vulnerabilities that speculation introduced.
(And keep in mind Intel has probably 90+% market share in the search for exploitable behavior.)
> The problems are just too deep and pervasive
One could also say that it strains credulity that the entire community failed to realize the existence of these vulnerabilities that are so fundamental to speculation, and yet here we are - that's exactly what happened.