Live data from Hacker News

ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

cyberus-technology.de

271–280 of 337 posts

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#271
post #124
post #72

Earlier quoted context omitted.

Intel and AMD don't have to share the same bugs for AMD to be worse. Consider you've got two sets of vulnerabilities: [1, 2, 3] and [2, 4, 5, 6, 7, 8]. If I label set 1 Intel, and set 2 AMD, then you can see how doing your research on Intel first will make it seem like Intel has 3x the vulnerabilities as AMD - even though it actually has half.

By your logic both of the sets could be infinite and we will never find out who has the more vulnerabilities.

Possibly.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#272
post #189

Earlier quoted context omitted.

Not sure why down voted, this sounds like the most logical reason

Because they’d eventually have to disclose when the vulnerability was discovered and that’d be extremely obvious what they’re doing?

Seemed to work out okay for the Equifax executives who sold stock before they publicly disclosed they had been breached.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#273
post #139

Earlier quoted context omitted.

You can't really find a good AMD workhorse laptop; all of them end up with some outdated 1080p displays at best :( There is like only one notebook with a decent HiDPI screen with Ryzen (some HP, but not a workhorse). There was also terrible problem with Mobile Ryzen drivers resolved only like a month ago.

1080p strikes me as the pinnacle of a workstation display for laptops right now since I highly doubt any productivity improvement from higher dpi is gonna beat out battery life in the vast majority of cases. Even in the one use case where it matters, 4k video production, theres a reasonable argument for using screens similar to what your consumers will use at least some of the time. Especially if it saves you money a…

Counterpoint to battery life argument against HiDPI displays are obviously retina MacBooks since 2012 (7 years ago). In addition I have a ZenBook with 3200x1800 and Core-M and its battery life is great. By outdated 1080p displays I also meant color accuracy, no HDR, bad viewing angles, slow latency etc. Seems like most AMD laptops are a dumping ground for old tech that can't be marketed as premium any longer. I'd rather suggest AMD to start manufacturing/contract somebody to develop high end models with their own brand to showcase what they can do.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#274
post #263

Earlier quoted context omitted.

> these flaws mostly affect Intel because they are the largest CPU manufacturer It doesn't have anything do to with how large Intel is. They have clearly made a more aggressive hardware design which has more corner cases to break. The designs are broken and microcode can patch some variants of these side channels but the overhead is becoming a problem. In this case it's not certain if microcode can address the proble…

It's undeniable that they've made aggressive hardware decisions, but... Intel dwarves their second largest competitor (AMD) in revenue by an order of magnitude... and remember, AMD sells GPUs as well. They are BY FAR the largest producer of CPUs for laptops, desktops, and servers. Note that on each of these platforms, arbitrary code execution is an issue. Now for phones? Less so. Aggressively locked down software can…

Note: “Dwarves” is the Tolkien variant spelling of a mythical race of beings. The normal English word is “Dwarfs”.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#275
post #265

Earlier quoted context omitted.

Your not, but the gentlemen your replying to is. Bet you can’t guess where and what he worked on?

Yup, I worked for a bit at Intel, but I don't speak for them, I wasn't involved in any of the designs under discussion, and everything I'm saying here is public knowledge in the computer architecture community. I figured that the perspective from the academic comparch world might be interesting.

[deleted]

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#276
post #265
post #193

Earlier quoted context omitted.

I’m not a CPU architect, but it seems like Intel saved a couple gates by putting garbage instead of zeroes in the pipeline.

Your not, but the gentlemen your replying to is. Bet you can’t guess where and what he worked on?

Not sure how to read this, but if you meant it as a personal attack that's totally not ok here.

https://news.ycombinator.com/newsguidelines.html

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#277

People should realize that ancient Chinese were оnto something when they told that all phenomena shall evolve only so much before they tip over the peak of maximum development and inevitably rumble downhill into overdevelopment. P.S. the Holy Church of Progress keeps flagging the herecy of I-Ching out of existence, may it prevail in its glorious ways. Curious fact: expressing your disagreement in written form takes m…

I like the I Ching too but could you please stop posting these and then deleting them? It's an abuse of the site.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#278
post #115

Earlier quoted context omitted.

You cannot give each VM their own core. The business model of the cloud is that multiple VMs with virtual cores run on a single real core.

At the low end, sure. At the medium-to-high end, each VM is bound to one or more physical cores of the host, or sometimes an entire host ("dedicated instances.") I don't know enough about the IaaS market to know what the relative revenues of low-end compute vs. medium-to-high-end compute are for your average vendor, though. Is most of the profit in the low end? I'm also curious on what the impact on margins would be…

The low end compute must be a substantial amount of revenue.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#279

Earlier quoted context omitted.

> Intel was also planning to wait for at least another 6 months before bringing this to light Of course, until the legally agreed date when they can dump shares so there’s no obvious proof that it’s insider trading. Isn’t that what (then) Intel CEO Brian Krzanich did after Meltdown/Spectre?

No. CPU vulns don’t affect Intel’s stock price.

History would appear to prove you wrong[1]. Yes, Intel's stock price rebounded that doesn't change that their stock price changed when the vulnerability became public.

[1]: https://qz.com/1171391/the-intel-intc-meltdown-bug-is-hittin...

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#280
post #220
post #189

Earlier quoted context omitted.

Because they’d eventually have to disclose when the vulnerability was discovered and that’d be extremely obvious what they’re doing?

It might be obvious, but that's exactly what Brian Krzanich did in 2017. He didn't get in any actual trouble for it even though the timing smelled blatantly like insider trading.

[deleted]
Post reply on HN