Earlier quoted context omitted.
That and off by one errors ;)
Concurrency You forgot 2) Cache invalidation and 3)
* naming things
* cache invalidation
* off by one errors51–60 of 130 posts
There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)
There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)
Your comment is disingenuous and dangerous.
Wow. This is bad for Intel. Industry experts have been expressing concerns for this for ten years. Does this open Intel up to possible repercussions?
> Industry experts have been expressing concerns for this for ten years. AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.
Looking back, I should have asked him how intel evaluates security risks considering how much of modern day computing uses it (which makes it an extremely valuable black hack exploit since it can work on practically every computer).
This image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!
There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)
Except that these bugs were all open on open source operating systems, as well... Do you think Linux wasn't affected by Spectre and Meltdown? That the BSDs aren't? That Xen isn't? Your comment is disingenuous and dangerous.
There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)
Except that these bugs were all open on open source operating systems, as well... Do you think Linux wasn't affected by Spectre and Meltdown? That the BSDs aren't? That Xen isn't? Your comment is disingenuous and dangerous.
I never said that opensource software is not affected, I said "not being affected as a user". Because opensource software, being peer-reviewed, will never try to exploit a CPU bug. Opensource software is, by default, non-malicious.
There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)
Some users will think it "not worth their time" to offer constructive commentary along with their downvote. Also, commenting on the downvotes you receive will invite more silent downvotes :P
If only he had come up with a catchy name and a logo, we would have listened.
This image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!
incredible how I (we) ran on buggy hardware for so long.
We should fund a tiny group for sane cpu design.