Live data from Hacker News

Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

perens.com

51–60 of 499 posts

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#51
post #26
post #5

It would seem that paired with https://news.ycombinator.com/item?id=17820248 that Intel is reeling back like a wounded animal. I'm intrigued as to what comes next - real innovation or dirty tactics to stay on top?

Why not both?!

Worked wonders for Nvidia.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#52
> The security fixes are known to significantly slow down Intel processors, which won’t just disappoint customers and reduce the public regard of Intel, it will probably lead to lawsuits (if it hasn’t already). Suddenly having processors that are perhaps 5% to 10% slower, if they are to be secure, is a significant damage to many companies that run server farms or provide cloud services.

Maybe I'm missing something here, but I was under the impression that the Spectre/Meltdown mitigations have a big performance penalty, but the more recent L1TF mitigations should have little or no impact, and that the new license only showed up recently on the new L1TF mitigation patches.

Is the L1TF mitigation actually a lot worse than I thought, or does this license apply to the earlier Spectre/Meltdown patches, or is Bruce Perens just being sloppy and conflating the two?

Either way, I agree with him that draconian license terms shouldn't be attached to bug fixes.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#53

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

but the sandboxes, think of the inescapable sandboxes!

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#54

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

"Many customers" meaning people and orgs running server software on direct hardware. Does your caching or database server run user provided code? Is it accessible to the outside in any way? If not, then maybe it doesn't need the patch.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#55

Sorry if I stress this even one more time, but we badly need 100% open iron, I mean something beefier than SiFive. If there is any effort in this direction, then, say for a year, most donations should be diverted over there. Closed hardware is becoming the unavoidable medium used to push closed firmware into everyone's system, that's a lot more important than benchmarks.

I doubt RISC V is going to solve the problem you're complaining about, even if it becomes "beefier." RISC V is going to be a launchpad for proprietary custom accelerators, which is great, but will still involve pushing closed firmware.

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#58

Earlier quoted context omitted.

Are lawyers running their business, or are business decision makers making business decisions?

So business decision makers made the decision to let their lawyers be business decision makers?

It certainly looks like that. Not sure it was the wisest move though...

Re: Intel Publishes Microcode Patches, No Benchmarking or Comparison Allowed

#59
post #54

> Another issue is whether the customer should install the fix at all. Many computer users don’t allow outside or unprivileged users to run on their CPUs the way a cloud or hosting company does. For them, these side-channel and timing attacks are mostly irrelevant, and the slowdown incurred by installing the fix is unnecessary. lol, javascript

"Many customers" meaning people and orgs running server software on direct hardware. Does your caching or database server run user provided code? Is it accessible to the outside in any way? If not, then maybe it doesn't need the patch.

[deleted]
Post reply on HN