Live data from Hacker News

“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

marc.info

1–10 of 130 posts

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#2
Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#4
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN.

Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works as designed, not a bug" is a bit hard to stomach.

But if it needs help drafting a better PR release, someone is welcome to point them to HN's comments section.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#5
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

IMO the first step would be disclosing all their tricks they implement outside of the specs they give. If researchers had adequate documentation of all the side effects that these tricks introduce then it could be properly audited.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#6
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

After all the history of shady things with Intel ME/AMT, hindering coreboot projects efforts, etc I highly doubt there will be people who want to do that. Hopefully this story will start a big change in Intel policies (more likely it is not though).

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#7
At least one of the recent exploits needs to be mitigated at the OS level (I haven't looked at the details carefully, but I know Microsoft and Linux are working on it). Is OpenBSD affected and if so, what are they doing to mitigate it?

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#8

Wow. This is bad for Intel. Industry experts have been expressing concerns for this for ten years. Does this open Intel up to possible repercussions?

When has any tech company ever had to face any sort of repercussions for bugs?

I wholeheartedly think they should have to. But they don't.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#9
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

IMO the first step would be disclosing all their tricks they implement outside of the specs they give. If researchers had adequate documentation of all the side effects that these tricks introduce then it could be properly audited.

Looking at how they behave the only thing I would expect from them is to not give free shovels when people are trying to dig. They will keep turtling until there's a new product they can push and rush everybody to ditch the "insecure predecessors".

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#10
post #4
post #2

Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.

I am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works…

A friend of mine "bought the dip" and profited about $100 in the first 20 seconds and it only got better as the day progressed.
Post reply on HN