Earlier quoted context omitted.
The patch that was under question was related to a workaround for Meltdown, which makes AMD's note regarding the lack of necessity in agreement with the paper. The Spectre paper seems to be a bit less specific on how platforms might differ under explotation but very clearly states that it was verified to be possible. Workarounds for that problem will likely be much more application specific from what I can tell, but…
Update: AMD has an official statement with a clear outline of the discussed vulnerabilities: https://www.amd.com/en/corporate/speculative-execution
Intel Responds to Security Research Findings
231–240 of 245 posts
Re: Intel Responds to Security Research Findings
#232Re: Intel Responds to Security Research Findings
#233Earlier quoted context omitted.
Intel should now recall the affected CPUs and ship new fixed CPUs without Intel "ME" for Management Engine, another well known open flaw. In the end, hardware and software devs in the 1970s were right. Operating systems like MULTICS and computers like PDP-11 got it right. MULTICS supported 16 rings and has many advanced features that almost everyone forgot and never implemented in newer OS - shame on all of us! Intel…
> Intel should now recall the affected CPUs and ship new fixed CPUs You think they have the tooling to manufacture drop-in replacements for up to decade old CPUs, even if they wanted to?
Re: Intel Responds to Security Research Findings
#234Earlier quoted context omitted.
Bet you a dollar some lawyer had to vet that three times over before they published it.
That same lawyer no doubt had to tell them that the following statement wouldn't fly without the addition of the word "believes": "Intel believes its products are the most secure in the world [ . . . ]"
Re: Intel Responds to Security Research Findings
#235This is probably one of the poorest and most defensive PR pieces I've read from a company in a long time, and it does not really make me sympathetic to them at all. > Intel and other technology companies have been made aware of new security research describing software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from computing devices that are operat…
Yeah, I had to read the “bug” or “flaw” part twice to be sure they're not saying it isn't a bug or flaw, they're only saying it isn't unique to Intel. And then as you say, they immediately mention AMD to imply that everyone has the issue, but they also avoid actually saying that. Your excellent analysis of what they're really saying reminds me of user thaumaturgy's analysis of Adancing Our Amazing Bet[1]. [1] https:/…
Re: Intel Responds to Security Research Findings
#236* sad trombone *
They're obviously not the most secure, as the Project Zero research shows. The whole press release has to be one of the most dismissive and snobbish PR pieces I've seen from a large corp.
Re: Intel Responds to Security Research Findings
#237This is probably one of the poorest and most defensive PR pieces I've read from a company in a long time, and it does not really make me sympathetic to them at all. > Intel and other technology companies have been made aware of new security research describing software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from computing devices that are operat…
Yeah, I had to read the “bug” or “flaw” part twice to be sure they're not saying it isn't a bug or flaw, they're only saying it isn't unique to Intel. And then as you say, they immediately mention AMD to imply that everyone has the issue, but they also avoid actually saying that. Your excellent analysis of what they're really saying reminds me of user thaumaturgy's analysis of Adancing Our Amazing Bet[1]. [1] https:/…
To add insult to this already cheap shot, it was flat out lies and AMD isn't vulnerable to all three variants.
This is just pathetic.
Re: Intel Responds to Security Research Findings
#238https://www.theregister.co.uk/2018/01/04/intels_spin_the_reg...
Re: Intel Responds to Security Research Findings
#239Earlier quoted context omitted.
We know that "AMD processors are not subject to the types of attacks that the kernel page table isolation feature protects against." E.g. that AMD does not need the patch that Intel does. That is not the same as saying AMD is not affected at all. We do not know what the actual bug that prompted this activity is. Nobody has revealed that information. It is possible that the bug affects AMD also but does not require th…
The followup sentence: "The AMD microarchitecture does not allow memory references, including speculative references, that access higher privileged data when running in a lesser privileged mode when that access would result in a page fault." That is a pretty specific reference to the root of the problem, and a pretty clear indication that AMD's design decisions protect against whatever the attack is. Sure, we may fin…
https://googleprojectzero.blogspot.com/2018/01/reading-privi...
Re: Intel Responds to Security Research Findings
#240Earlier quoted context omitted.
The followup sentence: "The AMD microarchitecture does not allow memory references, including speculative references, that access higher privileged data when running in a lesser privileged mode when that access would result in a page fault." That is a pretty specific reference to the root of the problem, and a pretty clear indication that AMD's design decisions protect against whatever the attack is. Sure, we may fin…
And, 17 hours later, we now know that there were three distinct vulnerabilities, of which one applies to AMD. https://googleprojectzero.blogspot.com/2018/01/reading-privi...