Earlier quoted context omitted.
If you trust all the code (and other inputs, or outputs) on all the VMs, and you are running it in a secure environment, you don't. I admit, it's possible I'm underestimating how common this is. Why you generally do need it is the above isn't true, and microcode has to be loaded at the hypervisor level for everyone or for no one
> it's possible I'm underestimating how common this is This is quite common in the engineering/research sectors, which love clusters. Think Sandia, oak ridge, etc. I also personally know of several private companies with research clusters. I'm curious how common hpcs are outside of the research community, because honestly I'm struggling to think of a practical need for one.
Intel publishes misleading benchmarks against AMD
141–150 of 209 posts
Re: Intel publishes misleading benchmarks against AMD
#142Earlier quoted context omitted.
HPC is not the real use case (target). The percentage of HPC compared to the rest of the target market (public cloud) is insignificantly small. The real question is do you trust any potential co-tenants in a public cloud that share a hypervisor with you, when said hypervisor does NOT have Spectre/Meltdown fixes applied? (There is only one correct answer...) Also you can fairly easily mitigate this in a public cloud s…
HPC is the use case in this thread, considering the topic is revolving around HPC benchmarks.
Re: Intel publishes misleading benchmarks against AMD
#143Earlier quoted context omitted.
Many? Anything running a browser needs it because of js. Anything running connected to the internet at all would be well advised to have them because you can take advantage of the exploits via the network stack. Anything running on a vm has to have them since microcode is set by the hypervisor. So, we're talking about desktops not used to browse the internet, and bare metal servers whose network stacks aren't exposed…
> So, we're talking about desktops not used to browse the internet, and bare metal servers whose network stacks aren't exposed to hostile actors? To be fair the context here is HPC. Nobody is installing Chrome on something like IBM's Summit supercomputer. Nor is it running "untrusted" code. It's configured to go as fast as possible, nothing more. Anyone in cloud hosting or desktop would be insane to not install spect…
I'm not really in the HPC space, but I can't really see any vp/cto/cio reasonably putting that asterisk on a security audit.
If you've got cyber insurance, you probably wouldn't be able to keep coverage if you did that.
Re: Intel publishes misleading benchmarks against AMD
#144There's often a long lead time between writing up benchmarks/white papers and publication. At my last employer it could take well over a month to let everyone have their 2 cents and get through Legal for approval. This is a long enough interval to explain the old/new GROMACS usage. As the saying goes, don't attribute to malice that which can be adequately explained by stupidity (including corporate bureaucracy).
Also, the difference in sub-NUMA configuration actually favors AMD as well. NPS=4 is optimal for AMD, as shown by ServeTheHome's own work earlier. Both systems are tested in their proper (fastest) configuration. Despite ServeTheHome's own previous work showing this, they're whining about it being different. But if Intel hadn't tested AMD in the proper configuration they would have complained about that too. Yeah, you…
Re: Intel publishes misleading benchmarks against AMD
#145Earlier quoted context omitted.
And please have at least two server quality 1gb nics. :-) My home router needs an upgrade.
Even Mac minis come with a 10gig NIC. Gotta future proof, right?
Re: Intel publishes misleading benchmarks against AMD
#146Earlier quoted context omitted.
For some reason, I doubt people in the server/workstation space don't know how to do this, especially if they are leaving double digit percentage gains on the table if they don't.
You are not supposed to disable the mitigations... Especially on servers and workstations... And keep in mind that the usual mitigations aren't even holistic. The only truly 100% secure fix for Spectre/Meltdown is to disable hyperthreading altogether.
Re: Intel publishes misleading benchmarks against AMD
#147Earlier quoted context omitted.
Is there a working JavaScript exploit for Spectre/Meltdown? I though it was just hypothetical.
There was a proof-of-concept included in the whitepaper: https://spectreattack.com/spectre.pdf That's a working exploit, not a hypothetical.
> Chrome intentionally degrades the accuracy of its high-resolution timer to dissuade timing attacks using performance.now() [62]. However, the Web Workers feature of HTML5 makes it simple to create a separate thread that repeatedly decrements a value in a shared memory location [24, 60]. This approach yields a high-resolution timer that provides sufficient resolution.
They did it on Chrome 62.0.3202, but SharedArrayBuffer was disabled in all major browsers right when spectre dropped. Chrome enabled it again in Chrome 67 if Full Site Isolation was enabled. Full site isolation is now enabled by default afaik.
So no, that is in no way a working exploit in any major browser I know of. There is no know spectre (or other variant) exploit that works in a default updated major browser (and there has never been as far as I know), but feel free to link any PoC's.
Re: Intel publishes misleading benchmarks against AMD
#148Sidebar question: Would anyone be interested if we adapted the TechEmpower benchmarks [1] to provide a composite score for the hardware environment? This could, in theory, give some insight into the capability of server hardware with respect to traditional web API-style requests. [1] https://www.techempower.com/benchmarks/
Re: Intel publishes misleading benchmarks against AMD
#149Earlier quoted context omitted.
Same. In an effort to minimalize, my work PC is a monitor with a NUC sitting under it. No bulky case, wires everywhere, etc. I've been trying for two years to find an AMD equivalent to no avail.
You can get a VESA mount Mini-ITX[1] case with a current-chipset (X570, etc.) motherboard, as well as all the other Mini-ITX options like monitor-mount base cases[2]. 1. https://www.amazon.com/Antec-ISK110-VESA-U3-Mini-ITX-Compati... 2. https://encrypted-tbn0.gstatic.com/images?q=tbn%3AANd9GcQQB9...
https://www.intel.ca/content/www/ca/en/support/articles/0000...
Re: Intel publishes misleading benchmarks against AMD
#150Earlier quoted context omitted.
Are we looking at the same charts? Both show AMD with a majority in the top 5.
I believe that when he said "They currently hold four of the top five results", he was talking about AMD, which does hold four of the top five results in both charts.