Live data from Hacker News

Intel Security Issue Update: Addressing Reboot Issues

newsroom.intel.com

51–60 of 129 posts

Re: Intel Security Issue Update: Addressing Reboot Issues

#51
post #47

Uhm, what a mess. This, just when Linux vendors began pushing updated intel-microcode packages (Ubuntu just released intel-microcode 3.20180108.0). Should we put the update on hold until this issue is hopefully resolved, or should we still update as suggested in the last paragraph of this Intel press release, somehow believing that the random reboots don't apply to "end users"?

It is a mess. I suggest that you and anyone else asking these questions pay attention to Microsoft a little bit, to receive all of the information that there is to be had on this.

Microsoft has been telling people about problems with the mitigations up-front. There are, for starters, Microsoft KnowledgeBase articles detailing problems with older AMD CPUs and with anti-virus softwares that behave like rootkit viruses resulting in systems that will not boot, and web log articles discussing the performance considerations for server systems.

* https://news.ycombinator.com/item?id=16076660

Re: Intel Security Issue Update: Addressing Reboot Issues

#52
post #47

Uhm, what a mess. This, just when Linux vendors began pushing updated intel-microcode packages (Ubuntu just released intel-microcode 3.20180108.0). Should we put the update on hold until this issue is hopefully resolved, or should we still update as suggested in the last paragraph of this Intel press release, somehow believing that the random reboots don't apply to "end users"?

Lenovo has put out an advisory about what to do with the BIOS updates that contain the microcode:

https://pcsupport.lenovo.com/de/en/product_security/PS500151

Withdrawn CPU Microcode Updates: Intel provides to Lenovo the CPU microcode updates required to address Variant 2, which Lenovo then incorporates into BIOS/UEFI firmware. Intel recently notified Lenovo of quality issues in two of these microcode updates, and concerns about one more. These are marked in the product tables with “Earlier update X withdrawn by Intel” and a footnote reference to one of the following:

1 – (Kaby Lake U/Y, U23e, H/S/X) Symptom: Intermittent system hang during system sleep (S3) cycling. If you have already applied the firmware update and experience hangs during sleep/wake, please flash back to the previous BIOS/UEFI level, or disable sleep (S3) mode on your system; and then apply the improved update when it becomes available. If you have not already applied the update, please wait until the improved firmware level is available.

2 – (Broadwell E) Symptom: Intermittent blue screen during system restart. If you have already applied the update, Intel suggests continuing to use the firmware level until an improved one is available. If you have not applied the update, please wait until the improved firmware level is available.

3 – (Broadwell E, H, U/Y; Haswell standard, Core Extreme, ULT) Symptom: Intel has received reports of unexpected page faults, which they are currently investigating. Out of an abundance of caution, Intel requested Lenovo to stop distributing this firmware.

Re: Intel Security Issue Update: Addressing Reboot Issues

#53
post #11

I just had a hard crash/reboot on a Dell running Windows 10 on an AMD processor, followed by a couple of auto updates. There was no indication of updates being available before the crash.

As I have just written elsewhere on this very page, you need to pay attention to the several KnowledgeBase and web log articles that Microsoft has been publishing on this subject as things develop.

* https://news.ycombinator.com/item?id=16076660

Re: Intel Security Issue Update: Addressing Reboot Issues

#55
post #13

I think it's a bit ironic that the text, in a sense, blames Google for these problems by calling them the "Google Project Zero Exploits" as if Google was some sort of cyber crime syndicate using their evil powers to exploit intel.

Wow, that's a good point. "...the exploits uncovered by Google Project Zero" would be much, much more appropriate.

The "Intel CPU fundamental design defects uncovered by Google" is more like it.

Re: Intel Security Issue Update: Addressing Reboot Issues

#56
post #16

This is -- to say the least -- frustrating. First, the busted microcode is still available on the Intel Download Center[1], without any warning that they recommend that you not, in fact, install it. Second, the press release is still being evasive: they have not merely "received reports"; they in fact know that it's causing issues, and the press release is avoiding the much stronger language that Intel is giving priv…

Why should they bother communicating clearly with their customers? Who are those customers going to turn to? AMD? ARM? Between Intel's numerous CPU bugs that they refused to refund customers for and ME, it's crystal clear what Intel thinks about their customers.

[deleted]

Re: Intel Security Issue Update: Addressing Reboot Issues

#57
post #40
post #37

Earlier quoted context omitted.

>Between Intel's numerous CPU bugs that they refused to refund customers for How do you propose this could work? Are side channel vulnerabilities in CPUs really bugs?

I mean, this one, yea. Speculative execution should not have side effects when wrong because it is Intel silently, sneakily breaking the model of how the CPU works (at least, if you only include the cache in how the PC works and not branch prediction). I would have expected, if I thought to ask, that items were not added to the cache or were removed from the cache if the branch was not retired.

[deleted]

Re: Intel Security Issue Update: Addressing Reboot Issues

#58
post #11

I just had a hard crash/reboot on a Dell running Windows 10 on an AMD processor, followed by a couple of auto updates. There was no indication of updates being available before the crash.

Out of curiosity, how do you suppose an Intel microcode update caused a blue screen on your system running an AMD processor?

Stolen IP, that's how!

Re: Intel Security Issue Update: Addressing Reboot Issues

#59
post #9

“We rushed a patch out and it’s causing problems we don’t understand yet. We’ll rush out an updated patch as soon as we can, so please don’t hesitate to install that.”

Please don't use quotation marks to make it look like you're quoting someone when you're not.

I think it was pretty clear from context that this was lighthearted and not a real quotation. Hell, I didn’t even include a source for where the quote allegedly came from.

Re: Intel Security Issue Update: Addressing Reboot Issues

#60

This is -- to say the least -- frustrating. First, the busted microcode is still available on the Intel Download Center[1], without any warning that they recommend that you not, in fact, install it. Second, the press release is still being evasive: they have not merely "received reports"; they in fact know that it's causing issues, and the press release is avoiding the much stronger language that Intel is giving priv…

They cant because every PR is written by a lawyer this is full protection mode against lawsuits who are coming anyway.
Post reply on HN