Live data from Hacker News

More Intel speculative execution vulnerabilities

mdsattacks.com

11–20 of 262 posts

Re: More Intel speculative execution vulnerabilities

#11
post #6

So Intel failed to mitigate the vulnerability when it was first reported. Then they extended the embargo from May until November. And they still didn't fix it. What's going on with Intel? Like they're going all in with lying in benchmarks against AMD and straight up forgetting what has been reported as security issues.

https://www.glassdoor.com/Reviews/Employee-Review-Intel-Corp...

>Company is dying and has no way to turn itself around.

>Culture is a "go along to get along" / don't rock the boat. Most workers are very passive. Inclusive culture focused on internal "networking" rather than winning. A lot of make work going on, probably 25% extra headcount

>Middle and upper management are in direct revolt against CEO and his plans. During my orientation (2nd quarter 2013) my orientation meeting was about how the CEO is wrong on his plans.

>Advice to Management

>Not much you can do. These problems are the result of near monopoly on PC CPUs for 20 years. This place is what Hewlett-Packard was probably like in 2000 (with the printer monopoly), the collapse is coming, but without starting over there is no way to fix it.

Re: More Intel speculative execution vulnerabilities

#12
post #6

So Intel failed to mitigate the vulnerability when it was first reported. Then they extended the embargo from May until November. And they still didn't fix it. What's going on with Intel? Like they're going all in with lying in benchmarks against AMD and straight up forgetting what has been reported as security issues.

Intel has become big and rich and has stopped (or perhaps never was) being very responsible. Given their fairly entrenched position in the industry, it's doubtful this strategy will impact their profit all that much and therefore we can expect to see more of this behaviour in the future.

Re: More Intel speculative execution vulnerabilities

#13
post #6

So Intel failed to mitigate the vulnerability when it was first reported. Then they extended the embargo from May until November. And they still didn't fix it. What's going on with Intel? Like they're going all in with lying in benchmarks against AMD and straight up forgetting what has been reported as security issues.

https://www.glassdoor.com/Reviews/Employee-Review-Intel-Corp... >Company is dying and has no way to turn itself around. >Culture is a "go along to get along" / don't rock the boat. Most workers are very passive. Inclusive culture focused on internal "networking" rather than winning. A lot of make work going on, probably 25% extra headcount >Middle and upper management are in direct revolt against CEO and his plans. D…

> This place is what Hewlett-Packard was probably like in 2000 (with the printer monopoly), the collapse is coming, but without starting over there is no way to fix it.

Interestingly, that printer monopoly seems to be doing fine today, given how I have to go to hp.com to get drivers for my Samsung printer.

Re: More Intel speculative execution vulnerabilities

#14
post #5

another 0-4% performance hit for skylake

The really damning part is that it applies even for processors that are supposedly fixed in silicon because Intel dropped the ball by playing wack-a-mole with proof of concept exploits instead of thoroughly building their chips with security in mind. If the history of Microsoft and Windows security is any indication, it'll take Intel many many years to turn that ship around. There's a question of whether AMD has been…

AMD’s speculative execution design is more risk aversive and it isn’t prone to many of the bugs identified so far. Of course this may change but I think it’s more than just scrutiny: AMD speculates less.

Plus, with better IPCs on Ryzen and much greater performance per dollar, why Intel?!

Re: More Intel speculative execution vulnerabilities

#15
post #13

Earlier quoted context omitted.

https://www.glassdoor.com/Reviews/Employee-Review-Intel-Corp... >Company is dying and has no way to turn itself around. >Culture is a "go along to get along" / don't rock the boat. Most workers are very passive. Inclusive culture focused on internal "networking" rather than winning. A lot of make work going on, probably 25% extra headcount >Middle and upper management are in direct revolt against CEO and his plans. D…

> This place is what Hewlett-Packard was probably like in 2000 (with the printer monopoly), the collapse is coming, but without starting over there is no way to fix it. Interestingly, that printer monopoly seems to be doing fine today, given how I have to go to hp.com to get drivers for my Samsung printer.

HP used to be much more. It was a real innovative company.

But the interesting parts have been spun out like: Agillent and Keysight.

HP Enterprise was also spun out.

Re: More Intel speculative execution vulnerabilities

#16
post #5

another 0-4% performance hit for skylake

The really damning part is that it applies even for processors that are supposedly fixed in silicon because Intel dropped the ball by playing wack-a-mole with proof of concept exploits instead of thoroughly building their chips with security in mind. If the history of Microsoft and Windows security is any indication, it'll take Intel many many years to turn that ship around. There's a question of whether AMD has been…

I don't think anyone seriously expected Intel to be able to thoroughly harden their chips against Spectre-style attacks given just a year to tweak their existing microarchitecture. They were able to move some permissions checks ahead of some speculative actions, but they simply haven't had enough time to design an architecture that can unwind all observable side-effects of mispredictions. It was obvious that all the near-term fixes in silicon would be equivalent to or only slightly better than the microcode or OS-based mitigations.

Re: More Intel speculative execution vulnerabilities

#18
Is it possible to apply the mitigations on an per-application level in Windows? IMHO it'd be pretty useful to be able have them on by default, but disable them for specific applications where you care about maximum performance and know that you won't be running untrusted code.

Re: More Intel speculative execution vulnerabilities

#19
post #18

Is it possible to apply the mitigations on an per-application level in Windows? IMHO it'd be pretty useful to be able have them on by default, but disable them for specific applications where you care about maximum performance and know that you won't be running untrusted code.

Tagging on with a similar query. I am on Windows 10. If I were to run Firefox in sandboxie, would be the attacker have to deal with an extra layer of security or does it offer no help?
Post reply on HN