Live data from Hacker News

Unexpected Page Fault In Virtualized Environment Advisory

intel.com

41–44 of 44 posts

Re: Unexpected Page Fault In Virtualized Environment Advisory

#41
post #2

Someone should make a graph quantifying the number of "mitigations" and performance impacting patch work for popular Intel SKU's since release. It would be interesting to see how many times they've patched the same processor and how much slower they are now than when they were made due to all the mitigations.

The inverse question is relevant as well: How many performance enhancements over the last 10 years were only possible because Intel ignored security?

Re: Unexpected Page Fault In Virtualized Environment Advisory

#44
post #13

Earlier quoted context omitted.

Is that actually better in this case? Intel found the issue internally. Nobody knows what it is. The advisory isn't sufficient information to figure it out. People can patch at their leisure, fairly sure that nobody is about to pop up with a 1-day exploit for it. With an open source CPU, by now someone would have looked at the commits that fixed the Verilog/microcode, figured out what the bug is, and there'd be a con…

You don't know that such a command doesn't exist for the Intel vulnerabilities, but hasn't been released to the wild or public.

I can be fairly sure, as otherwise Intel wouldn't be claiming the issue was found via their own internal audits, and likely someone else would be writing about it.
Post reply on HN