Earlier quoted context omitted.
Because they’d eventually have to disclose when the vulnerability was discovered and that’d be extremely obvious what they’re doing?
Is it obvious if they have an existing plan to sell shares and are simply waiting for it to trigger? They can reasonably claim they took this action to protect consumers until they had a better fix
ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
281–290 of 337 posts
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#282Earlier quoted context omitted.
Note that Spectre definitely affected AMD chips and in general these sorts of side channel attacks based on speculative execution are extremely likely to be effective against any chip (including AMD manufactured ones) that employ speculative execution though the precise implementation might have to be jiggered a bit.
Sure, but please don't downplay this, so far Intel CPU's are affected by way more vulnerabilities that could be exploited much easily. It is a no brainer to pick if I have to choose between AMD and Intel today.
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#283Earlier quoted context omitted.
The easiest prevention is to stop running untrusted code, or don't start doing so if you're not already. The "elephant in the room" with all these attacks starting from Spectre/Meltdown is that an attacker has to run code on your machine to be able to exploit them at all. To the average user, the biggest risk of all these side-channels is JS running in the browser, and that is quite effectively prevented by careful w…
I think that's a cop out. A system should be secure enough to isolate untrusted code.
At any rate, this is the world that we live in. Advise your non-tech friends to run updates to get the latest microcode and software mitigations. Install uBlock for them and block possible attack vectors aggressively (ads, trackers, etc). As a technical user, it's best to disable JavaScript completely by default and enable trusted third party JavaScript using e.g. uMatrix. Of course, this has other benefits too: creepy companies don't get to follow you around.
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#284Earlier quoted context omitted.
The whole "since they published that it happened, we've had a bunch of disclosures" which is a typical "I don't feel safer when people talk openly about unfixed vulnerabilities" argument.
Err no, no it's not. It's that there's been a ton more attention there. We're no more or less safe than we were before, we simply didn't know about the bugs that were there. (FYI, I've been a security researcher for 15+ years and work as the head of hacker education for HackerOne; I am very, very pro disclosure. :) )
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#285Earlier quoted context omitted.
Everyone who does speculative execution had Spectre issues, but Meltdown-style vulnerabilities have been mostly Intel-exclusive. These new ones are too.
Maybe because Intel has shipped a thousand more SKUs and millions more CPUs with Meltdown than ARM, for which the Cortex-A75 was a new design, and IBM, which doesn't ship huge numbers of either POWER or mainframe CPUs??
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#286So I'd love to post an Ask HN: Which AMD Laptops would you recommend for work, alternatives to Thinkpads? I've noticed some Thinkpads with AMD CPUs but I feel like I'm on virgin ground when it comes to AMD and their integrated GPU offerings.
https://www.huaweicentral.com/honor-magicbook-ryzen-7-versio...
The new 3700U model will probably be available on Aliexpress next month or so. I would consider it except Linux support is unknown and only 8GB of RAM.
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#287So I'd love to post an Ask HN: Which AMD Laptops would you recommend for work, alternatives to Thinkpads? I've noticed some Thinkpads with AMD CPUs but I feel like I'm on virgin ground when it comes to AMD and their integrated GPU offerings.
If you don't need a dedicated GPU, the APU offers from AMD are great. They have native linux drivers for everything (on the AMD side, double check the nic/touchscreen/touchpad). I'm using an HP envy x360 15z with a AMD Ryzen 2700u running gentoo and love it. The HP envy has a weird keyboard, but it was a good tradeoff for the AMD setup when I bought it last year. There is a much larger market in 2019 for AMD laptops,…
Next year with the 7nm mobile chips will probably be much better.
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#288So at what point do we start producing CPUs specifically aimed at running a kernel/userland? Why don't we have a CPU architecture where a master core is dedicated to running the kernel and a bunch of other cores run userland programs? I am genuinely curious. I understand that x86 is now the dominant platform in cloud computing. But it's not like virtualization needs to be infinitely nested, right? Why not have the ho…
> Why don't we have a CPU architecture where a master core is dedicated to running the kernel and a bunch of other cores run userland programs? How will your "userland core" switch to other userland programs safely? A pointer-dereference can be a MMap'd file, so its actually I/O. This will cause the userland program to enter kernel-mode to interact with the hardware (yes, on code as simple as blah = (this->next)... t…
User PU would stall on the "outermost" return and wait for another dispatch by kernel PU; it would also stall during context switches.
Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs
#289People should realize that ancient Chinese were оnto something when they told that all phenomena shall evolve only so much before they tip over the peak of maximum development and inevitably rumble downhill into overdevelopment. P.S. the Holy Church of Progress keeps flagging the herecy of I-Ching out of existence, may it prevail in its glorious ways. Curious fact: expressing your disagreement in written form takes m…
I like the I Ching too but could you please stop posting these and then deleting them? It's an abuse of the site.