Earlier quoted context omitted.
One must consider the potential damages that can happen when the default is wrong, as it’s nigh certain that people are going to be careless and not change it. If the desktop PC has wrong default the performance is bad. Still functional though. If in case of VM the default is wrong we will read another headline about how N million customers of $company got their personal data leaked.
I can't imagine a desktop PC that is unlikely to ever be used to browse the web. Spectre and simliar mitigations like disabling hyper threading are required to properly isolate javascript. Defaults should be set for the lowest common denominator. A lay computer user shouldn't have to understand and make decisions upon things like this.
OpenBSD was right to disable hyperthreading [video]
191–200 of 284 posts
Re: OpenBSD was right to disable hyperthreading [video]
#192Earlier quoted context omitted.
Minix only has a "huge install base" because of Intel ME firmware junk. Its not really meaningful, because the firmware could be pretty much any arbitrary OS and it would make zero difference to any end user. Tannenbaum himself didnt even know about Intel using MINIX in their ME firmware until recently, so that should show you how much relevance it has.
Yes, but it is significant that an industry leading company chose it over a RTOS or other embedded system for a high volume project.
Re: OpenBSD was right to disable hyperthreading [video]
#193Why aren’t the *BSD operating systems more popular in the server and workstation spaces?
Linux came after the BSDs, so you would think the BSDs would have won. There are many reasons Linux-based systems are generally much more popular than the BSDs in the server and workstation spaces. Here's why I think that happened: * GPL vs. BSD license. Repeatedly someone in the BSD community had the bright idea of creating a proprietary OS based on a BSD. All their work was then not shared with the OSS BSD communit…
When the AT&T lawsuit happened it had the direct effect of steering people from *BSD to Linux at a critical time for both, so I'd say that it was definitely a factor.
Re: OpenBSD was right to disable hyperthreading [video]
#194A wee bit offtopic, but if we look at the VW/dieselgate, and the aftermath of it all, and the class-actions, returns, refunds, etc, and hyundai/kia lies about gas milage and people getting refunds for gas... ...when is something like this going to happen to intel? We've bought CPUs with excpectations of promised performance (like people did with emission expectations and gas milage expectations), they messed up, and…
If I sell you a lock, and then 10 years later someone finds a vulnerability with the lock I sold you, should I refund you? That seems absurd. You are basically saying the product has to be perfect and the architects have to be able to see the future. Even if your hardware is formally verified, people can do physical attacks like listening to high frequency chirps of your cpu and using that to break security. Do you s…
Kryptonite did exactly this when someone figured out they could open their U-locks with a Bic pen barrel. Full recall of vulnerable products, with free replacement, regardless of age.
Re: OpenBSD was right to disable hyperthreading [video]
#195Earlier quoted context omitted.
Intel and others did give out a repair kit; they give you the option of disabling hyperthreading and a whole host of other optimizations. Those optimizations are both what provides this new side-channel of attack, and an immense speedup when they're enabled. You can't have one without the other.
Except they didn't advertise that way. They advertised the hyperthreaded performance, without disclosing its security implications.
Lock manufacturers can't advertise that their locks are hardened against specific yet-to-be-discovered attacks.
Intel can't advertise that their CPUs are hardened against specific yet-to-be-discovered attacks.
They can only provide mitigations after the fact.
Re: OpenBSD was right to disable hyperthreading [video]
#196Earlier quoted context omitted.
Indeed its the difference between lying and making a mistake. Off course they hoped with, plausible deniability, to mask those lies as mistakes: but they got caught. Hence the class action suits.
Have there been any rumors of internal discovery at Intel prior to any of these disclosures?
Re: OpenBSD was right to disable hyperthreading [video]
#197A wee bit offtopic, but if we look at the VW/dieselgate, and the aftermath of it all, and the class-actions, returns, refunds, etc, and hyundai/kia lies about gas milage and people getting refunds for gas... ...when is something like this going to happen to intel? We've bought CPUs with excpectations of promised performance (like people did with emission expectations and gas milage expectations), they messed up, and…
Even if you think any broken promise amounts to fraud, Intel didn't intentionally commit fraud.
So there's a strong argument that Intel, which is currently marketing their chips this way, is committing fraud. Maybe it could be argued that Intel didn't previously commit fraud. But as soon as the bugs became known, and Intel continued to market their chips as having hyperthreading, from that point forward they were committing fraud.
Re: OpenBSD was right to disable hyperthreading [video]
#198Earlier quoted context omitted.
If I sell you a lock, and then 10 years later someone finds a vulnerability with the lock I sold you, should I refund you? That seems absurd. You are basically saying the product has to be perfect and the architects have to be able to see the future. Even if your hardware is formally verified, people can do physical attacks like listening to high frequency chirps of your cpu and using that to break security. Do you s…
Downvoted for the straw man — Intel is currently selling processors with, e.g., 8 cores and 16 threads without any asterisks or caveats. That's in their official marketing materials. Currently. https://a.sellpoint.net/a/Qo3wL1no.jpg (via NewEgg) https://www.intel.com/content/www/us/en/products/processors/...
Has Intel ever said "we guarantee that hyperthreads are entirely isolated from one another?"
Re: OpenBSD was right to disable hyperthreading [video]
#199Earlier quoted context omitted.
Your desktop PC is regularly running largely unverified code, some of it potentially hostile: all the javascript in your browser.
Lol, amount of untrusted dll injections to mod, by default, unmoddable games; 3rd party VR tools and drivers; video and audio multiplexer drivers; compatibility drivers for normally unsupported console cameras/controllers etc; ultra demanding last gen console emulators; macro tools that are essentialy keyloggers; anti-cheat daemons running as admin to read memory of other processes; Windows gaming is wild! I literall…
If someone is patching DLLs they can figure out how to enable hyperthreading.
Re: OpenBSD was right to disable hyperthreading [video]
#200Earlier quoted context omitted.
Downvoted for the straw man — Intel is currently selling processors with, e.g., 8 cores and 16 threads without any asterisks or caveats. That's in their official marketing materials. Currently. https://a.sellpoint.net/a/Qo3wL1no.jpg (via NewEgg) https://www.intel.com/content/www/us/en/products/processors/...
And it's true... Has Intel ever said "we guarantee that hyperthreads are entirely isolated from one another?"
https://www.intel.com/content/www/us/en/architecture-and-tec...
> By combining one of these Intel® processors and chipsets with an operating system and BIOS supporting Intel® HT Technology, you can:
> * Run demanding applications simultaneously while maintaining system responsiveness
> * Keep systems protected, efficient, and manageable while minimizing impact on productivity