Live data from Hacker News

ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

cyberus-technology.de

281–290 of 337 posts

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#281
post #189

Earlier quoted context omitted.

Because they’d eventually have to disclose when the vulnerability was discovered and that’d be extremely obvious what they’re doing?

Is it obvious if they have an existing plan to sell shares and are simply waiting for it to trigger? They can reasonably claim they took this action to protect consumers until they had a better fix

Executives are allowed to sell at pre-agreed dates. If they do it on those dates then there’s nothing to prove, they just postpone the disclosure under any reason. Doesn’t make it smell less like insider trading, you just can’t prove it.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#282
post #197
post #11

Earlier quoted context omitted.

Note that Spectre definitely affected AMD chips and in general these sorts of side channel attacks based on speculative execution are extremely likely to be effective against any chip (including AMD manufactured ones) that employ speculative execution though the precise implementation might have to be jiggered a bit.

Sure, but please don't downplay this, so far Intel CPU's are affected by way more vulnerabilities that could be exploited much easily. It is a no brainer to pick if I have to choose between AMD and Intel today.

Way more known vulnerabilities. They also have a much smaller share of the market. I'd be surprised if researchers were targeting it as much.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#283
post #253

Earlier quoted context omitted.

The easiest prevention is to stop running untrusted code, or don't start doing so if you're not already. The "elephant in the room" with all these attacks starting from Spectre/Meltdown is that an attacker has to run code on your machine to be able to exploit them at all. To the average user, the biggest risk of all these side-channels is JS running in the browser, and that is quite effectively prevented by careful w…

I think that's a cop out. A system should be secure enough to isolate untrusted code.

The problem of running untrusted code is that the whole stack is a potential attack vector. From CPU to Javascript JIT compiler. Systems will never be secure enough to fully isolate untrusted code, because (1) people make dumb mistakes; (2) the incentives of most hardware/software vendors are profit, not security; (3) people have other priorities than security, e.g. performance.

At any rate, this is the world that we live in. Advise your non-tech friends to run updates to get the latest microcode and software mitigations. Install uBlock for them and block possible attack vectors aggressively (ads, trackers, etc). As a technical user, it's best to disable JavaScript completely by default and enable trusted third party JavaScript using e.g. uMatrix. Of course, this has other benefits too: creepy companies don't get to follow you around.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#284
post #179

Earlier quoted context omitted.

The whole "since they published that it happened, we've had a bunch of disclosures" which is a typical "I don't feel safer when people talk openly about unfixed vulnerabilities" argument.

Err no, no it's not. It's that there's been a ton more attention there. We're no more or less safe than we were before, we simply didn't know about the bugs that were there. (FYI, I've been a security researcher for 15+ years and work as the head of hacker education for HackerOne; I am very, very pro disclosure. :) )

Another security principle is involved: assume the worst case. If CPU vulnerabilities are a popular subject, they get fixed to some extent: it's much better than letting them be as a tool in the hands of private and government black hat hackers.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#285
post #205

Earlier quoted context omitted.

Everyone who does speculative execution had Spectre issues, but Meltdown-style vulnerabilities have been mostly Intel-exclusive. These new ones are too.

Maybe because Intel has shipped a thousand more SKUs and millions more CPUs with Meltdown than ARM, for which the Cortex-A75 was a new design, and IBM, which doesn't ship huge numbers of either POWER or mainframe CPUs??

Why would that make a difference? We're not talking about manufacturing defects, every single unit they sell has the problem, doesn't matter if they sell 10 or 10 million.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#286

So I'd love to post an Ask HN: Which AMD Laptops would you recommend for work, alternatives to Thinkpads? I've noticed some Thinkpads with AMD CPUs but I feel like I'm on virgin ground when it comes to AMD and their integrated GPU offerings.

Honor Magicbook looks interesting:

https://www.huaweicentral.com/honor-magicbook-ryzen-7-versio...

The new 3700U model will probably be available on Aliexpress next month or so. I would consider it except Linux support is unknown and only 8GB of RAM.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#287

So I'd love to post an Ask HN: Which AMD Laptops would you recommend for work, alternatives to Thinkpads? I've noticed some Thinkpads with AMD CPUs but I feel like I'm on virgin ground when it comes to AMD and their integrated GPU offerings.

If you don't need a dedicated GPU, the APU offers from AMD are great. They have native linux drivers for everything (on the AMD side, double check the nic/touchscreen/touchpad). I'm using an HP envy x360 15z with a AMD Ryzen 2700u running gentoo and love it. The HP envy has a weird keyboard, but it was a good tradeoff for the AMD setup when I bought it last year. There is a much larger market in 2019 for AMD laptops,…

It's not that large yet. There are sadly still no options with HiDPI screens (200+ dpi) or discrete AMD GPUs.

Next year with the 7nm mobile chips will probably be much better.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#288

So at what point do we start producing CPUs specifically aimed at running a kernel/userland? Why don't we have a CPU architecture where a master core is dedicated to running the kernel and a bunch of other cores run userland programs? I am genuinely curious. I understand that x86 is now the dominant platform in cloud computing. But it's not like virtualization needs to be infinitely nested, right? Why not have the ho…

> Why don't we have a CPU architecture where a master core is dedicated to running the kernel and a bunch of other cores run userland programs? How will your "userland core" switch to other userland programs safely? A pointer-dereference can be a MMap'd file, so its actually I/O. This will cause the userland program to enter kernel-mode to interact with the hardware (yes, on code as simple as blah = (this->next)... t…

> How will your "userland core" switch to other userland programs safely? A pointer-dereference can be a MMap'd file, so its actually I/O.

User PU would stall on the "outermost" return and wait for another dispatch by kernel PU; it would also stall during context switches.

Re: ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

#289
post #277

People should realize that ancient Chinese were оnto something when they told that all phenomena shall evolve only so much before they tip over the peak of maximum development and inevitably rumble downhill into overdevelopment. P.S. the Holy Church of Progress keeps flagging the herecy of I-Ching out of existence, may it prevail in its glorious ways. Curious fact: expressing your disagreement in written form takes m…

I like the I Ching too but could you please stop posting these and then deleting them? It's an abuse of the site.

I'll stop as soon as dysgraphic flaggers stop. The true abuse is muting a comment that doesn't offend anyone, just calling to contemplate a philosophy so different from the current mainline it hurts. Or does it? Are they triggered by 'people should'? Yeah, they should, but don't have to. Is the very notion of impossibility to improve things forever without changing their essence offensive? Any other reason, could you explain it, please?
Post reply on HN