10 ms·
"These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running them." Curious. All oth
by chrisb 9y ago
"These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running them."
Curious. All other reports I've read state that AMD CPUs are not vulnerable.
- wnevets 9y agoyeah the intel response page is filled with people claiming intel is evil for even mentioning amd https://news.ycombinator.com/item?id=16064545 https://news.ycombinator.com/item?id=16064545
- noncoml 9y agoIt's a developing story, but from the information we have so far, it does look like Intel involving AMD is a disingenuous since AMD processors are not affected by the most serious of the issues.
- mtkd 9y agoIt's too early to say which is ultimately the most real-world serious. From the Spectre note (which does affect AMD): In addition to violating process isolation boundaries using native code, Spectre attacks can also be used to violate browser sandboxing, by mounting them via portable JavaScript code. We wrote a JavaScript program that successfully reads data from the address space of the browser process running it. How quickly are we going to see attacks targeting BTC/ETH wallets, apps etc. on clients and cloud hosted exchanges?
- deleted 9y ago[deleted]
- alanfalcon 9y agoHardware wallet or bust right now, right? Use a private key that has never touched the internet?
- tiles 9y agoTo be fair, the Intel post alludes to collaborating with AMD/ARM on mitigating Spectre, but userspace memory leaking is wholly separate from kernel memory leaking (Meltdown, which only affects Intel processors).
- wintom 9y agoSounds like maybe SOME ARM and SOME AMD are implicated, especially since the Android ARM CPUs appear to be fine...
- justincormack 9y agoThe ARM white paper goes into detail https://developer.arm.com/-/media/Files/pdf/Cache_Speculation_Side-channels.pdf?revision=966364ce-10aa-4580-8431-7e4ed42fb90b&la=en https://developer.arm.com/-/media/Files/pdf/Cache_Speculatio...
- revelation 9y agoThere aren't really any special Android ARM CPUs, maybe they are confident it doesn't really work on Android because it's very difficult to get the timing precision and low-level assembly sequences in Java/ART compiled code. Though I wonder how that squares up with JNI. I think the key to the statement is in any case that you need to differentiate between what is possible on the processor architecture level when you have full software control, and what is possible on an operating system level, where 3rd party applications are further restricted in various arbitrary ways such as only allowed to use Java, limited access to high resolution timing primitives, etc. that can make practical exploitation impossible, even if the flaw is present. It's difficult to reason about because it's hard to tell if you can manipulate a JIT runtime into generating the code you need for the exploit to work - and as the JavaScript implementations show, the answer is often "yes".
- bitmapbrother 9y agoYou can develop Android applications in C/C++ using the NDK, thus, giving you full software control if needed.
- mtanski 9y agoJIT engines (and compilers) often generate a familiar instruction patterns. Many JIT engines Target specific languages (like JS) and as result have "simpler" optimizers (less time to do this) and possibly more stable instruction patterns. So my money is on somebody fuzzing the required JS code.
- noncoml 9y agoWe won't know until we have the full details. From the linux patches it looked like that AMD x86-64 processors were not affected. But the sentence you quote adds AMD back into play. Maybe some of its ARM processors? e.g. AMD Opteron A1100?
- MBCook 9y agoThey weren’t effected by the really bad Intel big names Meltdown. They’re still susceptible to Spectre.
- nine_k 9y agoLinks to descriptions of similar vulnerabilities in AMD and ARM processors would be very welcome.
- lettergram 9y agoHere's a list of what google tested: Intel(R) Xeon(R) CPU E5-1650 v3 @ 3.50GHz (called "Intel Haswell Xeon CPU" in the rest of this document) AMD FX(tm)-8320 Eight-Core Processor (called "AMD FX CPU" in the rest of this document) AMD PRO A8-9600 R7, 10 COMPUTE CORES 4C+6G (called "AMD PRO CPU" in the rest of this document) An ARM Cortex A57 core of a Google Nexus 5x phone [6] (called "ARM Cortex A57" in the rest of this document) https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html https://googleprojectzero.blogspot.com/2018/01/reading-privi...
- digikata 9y agoSo there's a bit of an unknown if AMD's most recent generation of processor has the Spectre vulnerability?
- sbx320 9y agoFrom the Spectre paper: > We have also verified the attack’s applicability to AMD Ryzen CPUs.
- lettergram 9y agoWe know that the scariest attack "meltdown", cannot be reproduced on AMD or ARM chips at all[1]. The second attack "Spectre" is also greatly mitigated due the neural network predicting pathways for the application. Thus it's unlikely/less-likely that you'll be able to access other locations in memory[2]. However, it's definitely possible. [1] https://meltdownattack.com/meltdown.pdf https://meltdownattack.com/meltdown.pdf [2] https://spectreattack.com/spectre.pdf https://spectreattack.com/spectre.pdf
- RandomBK 9y ago
- MBCook 9y agoSee the Twitter thread here: https://twitter.com/nicoleperlroth/status/948678006859591682 https://twitter.com/nicoleperlroth/status/948678006859591682 (Edit: there are 9 posts total, go to her user page to see them all) Seems there are two issues. One, called Meltdown, only effects Intel and is REALLY bad, but the kernel page table changes everyone is making fixes it. The other, dubbed Spectre, is apparently common to the way all processors handle speculative execution and is unfixable without new hardware. I’d like to know more about that but I haven’t seen anything yet. Whoever discovered this stuff on Google’s team deserves some sort of computer security Nobel prize.
- chainsaw10 9y ago> computer security Nobel prize While they're not as big of a deal AFAIK, we do have the Pwnie Awards: https://pwnies.com/ https://pwnies.com/
- londons_explore 9y agoI can't really see how it would be fixable even with new hardware. Speculative execution is fundamental to getting decent performance out of a CPU. Without it you should probably divide your performance expectations by 5 at least. Rolling back all state rather than just user visible state in the CPU is neigh on impossible. When you evict something from the cache, you delete it. Undeleting is hard. There are also a lot of other non-user-visible bits of state in a CPU.
- ytpete 9y agoCouldn't you do something like have a separate chunk of "speculative cache" which you only commit to the main cache once the speculatively-executed instructions are retired? Sounds complex, sure - but it seems like that would give you the performance benefits of speculative execution while still being able to roll back (or prevent in the first place) any cache-state side effects when branches were mispredicted. Could also imagine processors start segregating cache by privilege level. I guess part of the question you're raising is: are there so many different caches, translation buffers, etc. in a modern CPU that keeping 'uncommitted buffers' for the state of all of them would be just as complex as throwing a whole other core in there?
- azurezyq 9y agoYou can find the details below. They've tried AMD CPUs also. https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html https://googleprojectzero.blogspot.com/2018/01/reading-privi...
- forgot-my-pw 9y ago"We reported this issue to Intel, AMD and ARM on 2017-06-01" What!
- static_noise 9y agoHow much in advance do the intel managers have to register a stock sell?
- PuffinBlue 9y agoFor his sake, I hope longer than 6 months!
- chc 9y agoYou mean without getting whomped for insider trading? I don't think they're allowed to do it in advance at all.
- static_noise 9y agoAs far as I know they HAVE to register a trade in advance. I.E. three months ahead: "I will sell 600 shares on 15th of December if the share price is above 50". This information is public and other people can use this information before the trade actually happens.
- eindiran 9y agoIt looks like he registered for the trade in October, well after Intel was made aware of the issue.
- 9y ago
- btilly 9y agoAnd yet it also says that AMD devices running Android are not vulnerable. I'd be curious how those two statements should be reconciled.
- userbinator 9y agoNot exactly; it says "we are unaware of any successful reproduction of this vulnerability that would allow unauthorized information disclosure on ARM-based Android devices."