Live data from Hacker News

Intel CEO: Patches will come to 90% of chips in the next week

techcrunch.com

41–50 of 137 posts

Re: Intel CEO: Patches will come to 90% of chips in the next week

#41

This is only Spectre, not Meltdown. Meltdown requires KPTI, which depends on your OS. For OSs that did not enjoy months of advanced disclosure (which is: any OS that isn't Windows, MacOS or mainline Linux), that work is ongoing and will depend on the OS. (Speaking for SmartOS/illumos, that work is reasonably far along and making promising progress -- but we don't yet have a functional prototype.) As for Spectre, thes…

For reference, I received this email before today:

By now, we're sure most everyone have heard of the Meltdown and Spectre attacks. If not, head over to https://meltdownattack.com/ and get an overview. Additional technical details are available from Google Project Zero. https://googleprojectzero.blogspot.com/2018/01/reading-privi...

The FreeBSD Security Team was notified of the issue in late December and received a briefing under NDA with the original embargo date of January 9th. Since we received relatively late notice of the issue, our ability to provide fixes is delayed.

Meltdown (CVE-2017-5754) ~~~~~~~~~~~~~~~~~~~~~~~~ In terms of priority, the first step is to mitigate against the Meltdown attack (CVE-2017-5754, cited as variant 3 by Project Zero). Work for this is ongoing, but due to the relatively large changes needed, this is going to take a little while. We are currently targeting patches for amd64 being dev complete this week with testing probably running into next week. From there, we hope to give it a short bake time before pushing it into the 11.1-RELEASE branch. Additional work will be required to bring the mitigation to 10.3-RELEASE and 10.4-RELEASE.

The code will be selectable via a tunable which will automatically turn on for modern Intel processors and off for AMD processors (since they are reportedly not vulnerable). Since the fix for Meltdown does incur a performance hit for any transition between user space and kernel space, this could be rather impactful depending on the workload. As such, the tunable can also be overridden by the end-user if they are willing to accept the risk.

Initial work can be tracked at https://reviews.freebsd.org/D13797. Please note this is a work in progress and some stuff is likely to be broken.

Spectre (CVE-2017-5753 and CVE-2017-5715) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ When it comes to the Spectre vulnerabilities, it is much harder to sort these out. Variant 1 (CVE-2017-5753) is going to require some static analysis to determine vulnerable use cases that will require barriers to stop speculation from disclosing information it shouldn't. While we haven't done the analysis to determine where we are vulnerable, the number of cases here are supposed to be pretty small. Apparently there have been some Coverity rules developed to help look for these, but we are still evaluating what can be done here.

The other half of Spectre, variant 2 (CVE-2017-5715) is a bit trickier as it affects both normal processes and bhyve. There is a proposed patch for LLVM (https://reviews.llvm.org/D41723) that introduces a concept called 'retpoline' which mitigates this issue. We are likely to pull this into HEAD and 11-STABLE once it hits the LLVM tree. Unfortunately, the currently supported FreeBSD releases are using older versions of LLVM for which we are not sure the LLVM project will produce patches. We will be looking at the feasibility to backport these patches to these earlier versions.

There are CPU microcode fixes coming out when in concert with OS changes would also help, but that's a bit down the road at the moment.

If anything significantly changes I will make additional posts to clarify as the information becomes available.

Best regards, Gordon Tetlow with security-officer hat on

Re: Intel CEO: Patches will come to 90% of chips in the next week

#42
post #28

What I'm worried about is that it will be hard to avoid these security patches when you don't need them. Say you have a non-virtualized, non-shared server that only runs your own trusted code. I don't want to be forced to pay the performance penalty but it might be unavoidable without resorting to maintaining your own linux fork.

Do you trust all of the userland?

Is your machine internet connected?

Do you have any open ports?

Do you run everything as root?

If your answers are yes, no, no, and yes than it likely will make no difference. Otherwise (and the last one is just for fun to attempt to show you this is probably not a wise decision) you probably would do better to take this serious.

Re: Intel CEO: Patches will come to 90% of chips in the next week

#43
post #28

What I'm worried about is that it will be hard to avoid these security patches when you don't need them. Say you have a non-virtualized, non-shared server that only runs your own trusted code. I don't want to be forced to pay the performance penalty but it might be unavoidable without resorting to maintaining your own linux fork.

On Linux, pass "pti=off" on kernel command line.

Re: Intel CEO: Patches will come to 90% of chips in the next week

#44
post #39
post #25

I wonder what will the next big security hole. I'm becoming very pessimistic about how I can trust computers. Computers can do amazing thing, but software seems fragile, unreliable and untrustworthy. I have been keeping notes on paper for years now, and it doesn't look like it's going to change.

Internet-connected computers are more secure now than they ever have been. Just take the standard precautions: update your OS and don't install untrusted apps.

And do not visit untrusted webpages with javascript enabled? And how do you know which pages you can trust?

Re: Intel CEO: Patches will come to 90% of chips in the next week

#47

Earlier quoted context omitted.

Intel's not patching anything. They're relying on Windows, Linux and macOS patches to work around the vulnerability. Presumably that's how the 90% claim can be made. Very disingenuous of Intel tho. EDIT: There are microcode updates included in the OS updates: https://access.redhat.com/articles/3311301

> Very disingenuous of Intel tho This crisis has taken Intel, in my mind, from an American behemoth at the vanguard of technology to a sclerotic overgrown mess. Bugs happen, crises happen. When you're a $200 billion company, those mistakes scale deafeningly. The bugs are unfortunate, but not unreasonable. Intel's communication, however, from the first press release to crap like this, has been disingenuous to the poin…

Well, they may have been more honest than they intended to be when they said that the CPUs were operating ´as designed´. Tinfoil hat stuff.

Re: Intel CEO: Patches will come to 90% of chips in the next week

#48

I thought they already provided a microcode update?

Latest version on downloadcenter.intel.com is 20171117; no microcode update has been published since Spectre/Meltdown have been disclosed. edit: see below, not true; they haven't published it on their own site but have pushed microcode updates to redhat.

Found via @grsecurity about 15 minutes ago: https://downloadcenter.intel.com/download/27431/Linux-Proces...

Re: Intel CEO: Patches will come to 90% of chips in the next week

#49
This is how this terrible CEO tells us about microcode fixes, at a CES speech? Or is he even talking about a microcode update, or about the patches everybody else has been losing their lives working on? What a crap response to such a huge and existential issue.

Make a web page on the Intel site with concise, real information on what's going on and what to do. We're a week into disclosure and there's still no patch for most people's servers. A patch that takes up to a 30% performance hit but may not be necessary if there's going to be a microcode fix?

I know this is just a cute speech and debate practice session for the Intel execs, but I have servers that will have to get trashed because of the slowdown patch, they will be too slow to function in their current role and will need to be replaced. This is seriously affecting my life, my work schedule and my wallet. Please have real engineers provide real information here.

Re: Intel CEO: Patches will come to 90% of chips in the next week

#50

Earlier quoted context omitted.

Intel's not patching anything. They're relying on Windows, Linux and macOS patches to work around the vulnerability. Presumably that's how the 90% claim can be made. Very disingenuous of Intel tho. EDIT: There are microcode updates included in the OS updates: https://access.redhat.com/articles/3311301

> Very disingenuous of Intel tho This crisis has taken Intel, in my mind, from an American behemoth at the vanguard of technology to a sclerotic overgrown mess. Bugs happen, crises happen. When you're a $200 billion company, those mistakes scale deafeningly. The bugs are unfortunate, but not unreasonable. Intel's communication, however, from the first press release to crap like this, has been disingenuous to the poin…

As much as I hate to say it, I think the Intel PR machine is working stunningly.

Every geek I speak to will tell you the world's on fire. Every non-geek I speak to responds with "oh, really? if it's such a big problem how come no-one has heard about it? Oh, ok, well there might have been that one headline..."

I am infuriated by Intel's response no end, however I'm also somewhat impressed. They seem to have completely avoided a PR disaster and their stock price is largely unaffected.

Post reply on HN