Live data from Hacker News

“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

marc.info

51–60 of 130 posts

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#51
post #46

Earlier quoted context omitted.

That and off by one errors ;)

Concurrency You forgot 2) Cache invalidation and 3)

The two most difficult things in software development.

    * naming things
    * cache invalidation
    * off by one errors

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#52

There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)

Some users will think it "not worth their time" to offer constructive commentary along with their downvote. Also, commenting on the downvotes you receive will invite more silent downvotes :P

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#53

There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)

Except that these bugs were all open on open source operating systems, as well... Do you think Linux wasn't affected by Spectre and Meltdown? That the BSDs aren't? That Xen isn't?

Your comment is disingenuous and dangerous.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#54

Wow. This is bad for Intel. Industry experts have been expressing concerns for this for ten years. Does this open Intel up to possible repercussions?

> Industry experts have been expressing concerns for this for ten years. AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.

I work with a bunch of hardware engineers who used to work at intel and the really knowledgeable ex-intel guy I know said speculative execution has always been known to be risky but actually exploiting it was presumed to be very difficult/impossible.

Looking back, I should have asked him how intel evaluates security risks considering how much of modern day computing uses it (which makes it an extremely valuable black hack exploit since it can work on practically every computer).

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#56

There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)

Except that these bugs were all open on open source operating systems, as well... Do you think Linux wasn't affected by Spectre and Meltdown? That the BSDs aren't? That Xen isn't? Your comment is disingenuous and dangerous.

I think their point is the exploit code would be obvious in open source applications and you could choose not to run them. Violates the defense in depth precaution.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#57

There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)

Except that these bugs were all open on open source operating systems, as well... Do you think Linux wasn't affected by Spectre and Meltdown? That the BSDs aren't? That Xen isn't? Your comment is disingenuous and dangerous.

You're (and most likely all downvoters) completely missing the point.

I never said that opensource software is not affected, I said "not being affected as a user". Because opensource software, being peer-reviewed, will never try to exploit a CPU bug. Opensource software is, by default, non-malicious.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#58
post #52

There's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)

Some users will think it "not worth their time" to offer constructive commentary along with their downvote. Also, commenting on the downvotes you receive will invite more silent downvotes :P

I'm astounded by the level of ignorance and professionalism of some downvoters then.

Re: “Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)

#60

This image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!

same, and don't bother reading too much, the best bugs came after ...

incredible how I (we) ran on buggy hardware for so long.

We should fund a tiny group for sane cpu design.

Post reply on HN