5 ms·
Will there be any way to disable or block the upcoming patches and keep the performance for those of us who really just don't have any reason to care about inte
by throwaway613834 9y ago
Will there be any way to disable or block the upcoming patches and keep the performance for those of us who really just don't have any reason to care about inter-process information leakage on our personal computers?
Edit: I'm (also) wondering about Windows, in case anyone knows yet.
- JoachimSchipper 9y agoYes, the work-around can be disabled via a boot-time argument.
- throwaway613834 9y agoThank you! Do you know if this will be true for Windows as well, or just Linux?
- pixl97 9y agoJust don't do this if you have PII, HIPAA, or PCI data on your computer.
- deleted 9y ago[deleted]
- stusmall 9y agoEven then and if they don't care about their own safety, they should patch for the rest of us. Who knows how long until their unpatched system will get pwned from some other vulnerability and end up in some botnet just spreading the pain.
- uniformlyrandom 9y agoFrom the merge commit: +#ifdef CONFIG_PAGE_TABLE_ISOLATION +# define DISABLE_PTI 0 +#else +# define DISABLE_PTI (1 << (X86_FEATURE_PTI & 31)) +#endif PS - MSFT has not published relnotes, so we do not know yet. We'll find out soon enough.
- throwaway613834 9y agoI meant disable at run time, not disabling via recompiling your own kernel.
- uniformlyrandom 9y agoThat is also in there. You can either specify "pti off" or "nopti" as a boot parameter. +void __init pti_check_boottime_disable(void) ... + ret = cmdline_find_option(boot_command_line, "pti", arg, sizeof(arg)); + if (ret > 0) { + if (ret == 3 && !strncmp(arg, "off", 3)) { + pti_print_if_insecure("disabled on command line."); + return; + } + if (ret == 2 && !strncmp(arg, "on", 2)) { + pti_print_if_secure("force enabled on command line."); + goto enable; + } + if (ret == 4 && !strncmp(arg, "auto", 4)) + goto autosel; + } + + if (cmdline_find_option_bool(boot_command_line, "nopti")) { + pti_print_if_insecure("disabled on command line."); + return; + } + +autosel: + if (!boot_cpu_has_bug(X86_BUG_CPU_INSECURE)) + return;
- stusmall 9y agoPlease just don't. It isn't worth the pain and risk just to have a little faster system. Maybe you don't care about this patch, but you will need others that are dependent on it. Just patch.
- throwaway613834 9y ago> Please just don't. It isn't worth the pain No, it very much is. > and risk No, there is no risk. I already run everything as admin. > just to have a little faster system. 5-30% is not "a little". > Maybe you don't care about this patch Indeed. And I expect many other power users also don't (but regardless, this is irrelevant). > but you will need others that are dependent on it. Well when that actually becomes a problem I will act accordingly. If more patches like this pop up I obviously won't install any of them. If there's a patch for a drive-by browser exploit depending on this, that will obviously be a different story. > Just patch. Hell no. My patching this makes my computer slower while providing exactly zero benefit to anyone.
- stusmall 9y ago>Well when that actually becomes a problem I will act accordingly. I don't mean to be rude but if you are having to ask how to disable automatic updates then you probably aren't someone who keeps up to date with all the latest issues. When it becomes problem, you just won't know. Let your OS vendor do all this for you. They are good at it.
- throwaway613834 9y ago> I don't mean to be rude but if you are having to ask how to disable automatic updates then you probably aren't someone who keeps up to date with all the latest issues. When it becomes problem, you just won't know. ...Wow. First of all, that's not what I asked. I asked how to disable or block this patch. Blocking "automatic updates" is neither equivalent to disabling this patch (post-install) nor to blocking it (pre-install). Second of all, I'm running Windows 8.1, on which I can actually block updates easily. I don't know if I can be picky about which patches I block on 10 because I have barely used it, but I will have to start using it soon and I really don't want to waste time installing the update only to find out I can no longer uninstall it. And third of all, you're really spewing nonsense. I've done security work in the past which I don't care to post details about here anonymously. I still keep up with security news regularly and I actually look into the update details before installing them (which should be obvious if you read my previous comment on how I said what I do depends on the actual updates). None of which you need to believe (and I really don't care if you don't), except for the minor caveat that if you're trying to be convincing, this holier-than-thou attitude moves you well in the opposite direction.