Live data from Hacker News

Microsoft disables Spectre mitigations as Intel’s patches cause instability

securityweek.com

111–120 of 329 posts

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#111

Earlier quoted context omitted.

Intel doesn't care. What choice do we have?

Vote with your wallet. That's really the only thing that you can do. Intel is too comfortable in their position as market leader. Until they start to feel some pressure, they have shown they don't really care. I know AMD is not a perfect company either, but I elected to buy a Ryzen processor for my upcoming build. People need to at least consider the competition without defaulting to "I need a processor, I buy the la…

I understand your point, and agree with the spirit of it, but a few consumers buying Ryzen chips isn't going to make one bit of difference. A couple data centers buying dozens of racks of them, however, would be more measurable. Hit em in the B2B not the B2C.

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#113
post #109

Earlier quoted context omitted.

Aaaaaand here comes the Linux defending! OK... > But keep in mind that if your system can't cope with this what you've done there is engineer in unreliability It's weird that you're blaming my operating system's problems on me . "My system" is something a ton of other people wrote, and this is the case for pretty much every user of every OS. I'm not engineering anything into (or out of) my system so I don't get the "…

> ...but it happens more often than I would like that I update Linux (Ubuntu) and, lo and behold, I can't really use any programs until I reboot... Ubuntu developer here. This doesn't happen to me in practice. Most updates don't cause system instability. I rarely reboot. Firefox is the most noticeable thing. After updating Firefox (usually it's a security update), Firefox often starts misbehaving until restarted. But…

Development release? Currently I'm on 16.04, and I've never been on a development release of anything on Ubuntu. I'm just describing the behavior I usually see in practice (which it seems someone attributed to "D-BUS" [1]). Obviously the logon session doesn't get messed up if all I'm updating is something irrelevant like Firefox, but if I update stuff that would actually affect system components then there's a good chance I'll have to reboot after the update or I'll start seeing weird behavior. This has generally been my experience ever since... any Ubuntu version, really. It's almost ironic that the most robust thing to update in practice is the OS kernel.

[1] https://news.ycombinator.com/item?id=16257060

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#114

Earlier quoted context omitted.

Before Intel Core processors became the standard hot processor I was an AMD guy. I'm heading back towards that route. This means no Macbook or Surfacebook for my next development laptop for me. If anyone wants my money they better build a developer worthy laptop with an AMD processor and a sweet AMD graphics card. Also AMD is working on providing open source GPU Vulkan drivers.

This one [1] seems like a good choice in terms of performance, but certainly no MBP in terms of portability. [1] - https://www.asus.com/uk/Laptops/ROG-Strix-GL702ZC

I already have an ASUS ROG laptop so this sounds like I'm sticking to them! Thank you, was hoping they'd add in AMD.

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#115
post #108

Earlier quoted context omitted.

CPUs from AMD are not vulnerable to Meltdown, but are vulnerable to both versions of Spectre. https://www.amd.com/en/corporate/speculative-execution

Damn! So, practically, no modern processor (or consumer laptop, or enterprise server) is safe from Spectre? Time to go off the beaten path.

I think it's safe to assume that pratical mitigations will eventually surface, the biggest issue is probably around the cost in performance. Shaving 30% (or whatever) of the worlds computing power in one fell swoop is kind of a big deal.

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#116

Earlier quoted context omitted.

Vote with your wallet. That's really the only thing that you can do. Intel is too comfortable in their position as market leader. Until they start to feel some pressure, they have shown they don't really care. I know AMD is not a perfect company either, but I elected to buy a Ryzen processor for my upcoming build. People need to at least consider the competition without defaulting to "I need a processor, I buy the la…

I understand your point, and agree with the spirit of it, but a few consumers buying Ryzen chips isn't going to make one bit of difference. A couple data centers buying dozens of racks of them, however, would be more measurable. Hit em in the B2B not the B2C.

I agree with you, and you are right. However, most people aren't making decisions about what types of chips to use in a data center. It would be wonderful if the people in those positions explored non-Intel options. For the average consumer, all we can do is choose which company we buy a CPU from every few years. People buying Ryzen chips incentivizes AMD to keep making chips and stay in the market. Competition is good for consumers. I totally get that it is a lot more complex than that, but I personally feel like it's the best we can do as the average consumer.

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#117
post #47

Earlier quoted context omitted.

I came here to ask the same thing. How did these folks squander six months?

I think Spectre may have appeared later, after Meltdown? Remember the investigations into what's possible were proceeding in parallel with the attempted fixes. Also, CPU design changes take a long time. 6 months may seem a long time from the perspective of HackerNews node.js type hackers, but it's a bit harder to patch decades worth of CPU microcode than a website.

Reading over googles project0 page it reads as if they told AMD about the issues on 2017-06-01 why would they do this if it were meltdown only?

also look at the exploit numbering:

Variant 1: bounds check bypass (CVE-2017-5753) Variant 2: branch target injection (CVE-2017-5715) Variant 3: rogue data cache load (CVE-2017-5754)

according to https://cve.mitre.org/cve/identifiers/ this is sequence based so `Variant 2` was recorded to CVE before v1 and v3.

I get it may take a long time (that is fine even if the patches took a few more days), what I don't get is that they released it to production (server) envs seemingly without testing. Surely even rudimentary testing (deploying on a few 1000 different server platforms for a few hours at least should be something that Intel does for all microcode updates, after all they are rather more important than js Node packages as you point out)

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#118

So what can I do for my next self-built pc? Get some AMD equipment, or is that not enough?

AMD have released patches (to reduce the near-zero risk of exploit to 0 risk) and they are not having any instability issues! so yes go with AMD

for server, Epyic is now finally available to purchase for desktop workstation Threadripper for desktop RyZen

for mobile... not many newer cpus out yet.. need to wait :(

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#119

Earlier quoted context omitted.

I understand your point, and agree with the spirit of it, but a few consumers buying Ryzen chips isn't going to make one bit of difference. A couple data centers buying dozens of racks of them, however, would be more measurable. Hit em in the B2B not the B2C.

I agree with you, and you are right. However, most people aren't making decisions about what types of chips to use in a data center. It would be wonderful if the people in those positions explored non-Intel options. For the average consumer, all we can do is choose which company we buy a CPU from every few years. People buying Ryzen chips incentivizes AMD to keep making chips and stay in the market. Competition is go…

For sure. Like I said, I agree with the spirit, and you can obviously only do things within your own sphere of influence. I'm also planning on doing a Ryzen build for my next PC. I'm just trying to be realistic to say that even thousands of consumers switching won't make a huge dent in their bottom line. B2B is really the only way to influence a company as large as Intel, unfortunately.

Re: Microsoft disables Spectre mitigations as Intel’s patches cause instability

#120

So what can I do for my next self-built pc? Get some AMD equipment, or is that not enough?

AMD equipment should be fine, current-gen Ryzen/Threadripper is more than adept at workstation tasks and next-gen Ryzen (named Ryzen 2 and Threadripper 2) will edge out any advantage that Intel's CPUs have.
Post reply on HN