25 ms·
“Intel Core 2 bugs will assuredly be exploitable from userland code” (2007)
- linohh 9y agoHas HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
- rdtsc 9y agoI am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works as designed, not a bug" is a bit hard to stomach. But if it needs help drafting a better PR release, someone is welcome to point them to HN's comments section.
- busterarm 9y agoA friend of mine "bought the dip" and profited about $100 in the first 20 seconds and it only got better as the day progressed.
- 013a 9y agoIf they need help, they should look at Google's release. Despite effectively saying the same thing, Intel's is disgusting and defensive, like a guilty man in a police interview yelling "I didn't do it!" Google's is facts, no bullshit language, and effective.
- JdeBP 9y agoLike so. * http://www.theregister.co.uk/2018/01/04/intel_meltdown_spectre_bugs_the_registers_annotations/ http://www.theregister.co.uk/2018/01/04/intel_meltdown_spect... https://news.ycombinator.com/item?id=16064545 https://news.ycombinator.com/item?id=16064545 (https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ https://newsroom.intel.com/news/intel-responds-to-security-r...) * https://news.ycombinator.com/item?id=16072368 https://news.ycombinator.com/item?id=16072368 (https://newsroom.intel.com/news-releases/intel-issues-updates-protect-systems-security-exploits/ https://newsroom.intel.com/news-releases/intel-issues-update...) * https://news.ycombinator.com/item?id=16067245 https://news.ycombinator.com/item?id=16067245 (https://www.amd.com/en/corporate/speculative-execution https://www.amd.com/en/corporate/speculative-execution) * https://news.ycombinator.com/item?id=16068118 https://news.ycombinator.com/item?id=16068118 (https://developer.arm.com/support/security-update https://developer.arm.com/support/security-update) * https://news.ycombinator.com/item?id=16072912 https://news.ycombinator.com/item?id=16072912 (http://blog.dustinkirkland.com/2018/01/ubuntu-updates-for-meltdown-spectre.html http://blog.dustinkirkland.com/2018/01/ubuntu-updates-for-me...) * https://news.ycombinator.com/item?id=16071769 https://news.ycombinator.com/item?id=16071769 (https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAn...) * No headline, although mentioned at https://news.ycombinator.com/item?id=16074531 https://news.ycombinator.com/item?id=16074531 and elsewhere (https://www.freebsd.org/news/newsflash.html#event20180104:01 https://www.freebsd.org/news/newsflash.html#event20180104:01) * https://news.ycombinator.com/item?id=16076660 https://news.ycombinator.com/item?id=16076660 (https://support.microsoft.com/en-gb/help/4072699/important-information-regarding-the-windows-security-updates-released https://support.microsoft.com/en-gb/help/4072699/important-i... https://support.microsoft.com/en-gb/help/4072698/windows-server-guidance-to-protect-against-the-speculative-execution https://support.microsoft.com/en-gb/help/4072698/windows-ser... ) * https://news.ycombinator.com/item?id=16075348 https://news.ycombinator.com/item?id=16075348 (https://support.apple.com/en-gb/HT208394 https://support.apple.com/en-gb/HT208394) * https://news.ycombinator.com/item?id=16076175 https://news.ycombinator.com/item?id=16076175 (https://lists.debian.org/debian-security-announce/2018/msg00000.html https://lists.debian.org/debian-security-announce/2018/msg00...) * https://news.ycombinator.com/item?id=16076328 https://news.ycombinator.com/item?id=16076328 (https://lists.opensuse.org/opensuse-updates/2018-01/msg00000.html https://lists.opensuse.org/opensuse-updates/2018-01/msg00000...)
- wasx 9y ago>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention security minded users) that require technology that is both resistant to meltdown and not underperforming hardware. It's silly to act like this is a storm in a teacup because the HN community is up in arms over it. Monopolies fall, and the loss of trust and key clients tends to precipitate that fall. >But if it needs help drafting a better PR release, someone is welcome to point them to HN's comments section. Their PR was shocking, but on the order of things people are upset about over this incident, this is literally at the bottom.
- rdtsc 9y ago> They can a handle a bit of criticism from a bunch of nerds on HN. It was a tongue-in-cheek response to OPs statement that we should feel bad for Intel and offer it help. I suggested that it needs help drafting a better PR release that's a bit more honest and straightforward. > Can they handle the loss of faith from big companies? With a $200B capitalization they certainly can. > Seems to me that AMD et al have now got the perfect opportunity to erode Agreed. The next step is to see if any of the large cloud providers or PC manufacturers will announce they are buying AMD CPUs. I hope because I'd like to be able to buy cheaper CPUs and have more competitors in the market. But realistically I kind of doubt it. At the end of the day INTC's stock hasn't moved that much. The performance hit as reported by Google didn't seem to as big.
- cat199 9y ago> At the end of the day INTC's stock hasn't moved that much. nor should it.. huge stock (so less speculators), many products besides x86 PC processors, and their reaction/fix to this & subsequent impact to actual earnings hasn't shaken out.. not pro or against intel. but mentioning this as concerns market stuffs.
- user5994461 9y ago
- RachelF 9y agoThe Register did a great analysis of turning the Intel Press release into English. "We translated Intel's attempt to spin its way out of CPU security bug PR nightmare as Linus Torvalds lets rip on Chipzilla" https://www.theregister.co.uk/2018/01/04/intel_meltdown_spectre_bugs_the_registers_annotations/ https://www.theregister.co.uk/2018/01/04/intel_meltdown_spec...
- baldfat 9y ago> It is effectively a monopoly in the desktop and server market But it couldn't be better timing for ARM. AMD isn't the competition (Though this helps them a little bit) it really is all about ARM and it is going to get a lot more attension with this. Windows runs on ARM now. CPUs can't get much smaller. It is now how many cores and thermal control you can place on a waffer. ARM has the advantage in both of those. We just have to learn how to utilize multiple cores better than we are now.
- foobiekr 9y agoWhich ARM? Have you ever even looked at ARM implementation errata? At the errata for people doing semi-custom ARM like Cavium? Do you think that those companies are as diligent as Intel? I can’t say anything about ARM vendors, but I’m pretty familiar with MIPS and PowerPC errata from chips in the mid-2000s and they generally made Intel look 10x as professional and careful.
- mannykannot 9y agoSaying "it is not a flaw, it is working as designed", when that design has led to a demonstrated exploit, marks one as either clueless or duplicitous. Why would a company as large as Intel choose to present itself as such? I guess it thinks we are too dumb to notice (Intel did say it is not a flaw in its press release; I don't know whether it explicitly tried the "working as designed" excuse, but the no-flaw claim by itself is nonsense, regardless.)
- rdtsc 9y agoMy guess is that the memo, besides the marketing channels was also filtered through the legal department and they advised not to admit guilt as they probably expect to be sued at some point. Then a clear admission on their part would be slam dunk.
- mannykannot 9y agoThat is probably so, though if it came to being sued, I guess the plaintiffs' counsel would be ready to point out the flaws in that line of thinking. On the other hand, Intel's stock price did recover in response, reversing the somewhat panicked or speculative drop earlier in the day, so perhaps this was mainly for the market.
- colemannugent 9y agoIMO the first step would be disclosing all their tricks they implement outside of the specs they give. If researchers had adequate documentation of all the side effects that these tricks introduce then it could be properly audited.
- randomString1 9y agoLooking at how they behave the only thing I would expect from them is to not give free shovels when people are trying to dig. They will keep turtling until there's a new product they can push and rush everybody to ditch the "insecure predecessors".
- tedunangst 9y agoSomething like adding "Implicit caching occurs when a memory element is made potentially cacheable, although the element may never have been accessed in the normal von Neumann sequence. Implicit caching occurs on the P6 and more recent processor families due to aggressive prefetching, branch prediction, and TLB miss handling." to the developer's manual.
- xvilka 9y agoAfter all the history of shady things with Intel ME/AMT, hindering coreboot projects efforts, etc I highly doubt there will be people who want to do that. Hopefully this story will start a big change in Intel policies (more likely it is not though).
- jlgaddis 9y ago(playing devil's advocate here, to be clear) What leads you to believe that Intel has any reason to think that there's an issue that needs changed? Or that "the community" knows anything about their business processes or what Intel should do? They have their highly-paid C-levels to figure that out. From their perspective, there's no problem. Nothing needs fixin'. You'll keep buying their CPUs, anyways -- you don't really have much of a choice, do you? [0] Just go install those updates from your vendor(s) and go about your business, you'll be fine. No big deal, nothing to worry about. Carry on. Just like you did with that recent little ME/AMT issue. There'll be another issue to deal with in a few days and everyone will forget all about this one. [0]: Oh, you're gonna replace all your infrastructure with AMD's CPUs, huh? Yeah, sure you are. They're no different.
- vbezhenar 9y agoBasically buying new Intel processor to replace old will yield 5-60% performance in I/O-heavy workloads even without any other changes but fixed processor bug, unless you're ready to tweak with your OS settings and fine with potential vulnerability. With proper marketing they can make huge profits from this situation. Sure, you can buy AMD, but Intel is still faster for many benchmarks. Given that they knew about bug for 7 months, I think that soon new processors will be without Meltdown bug.
- mindentropy 9y agoYou are right in your assessment. This is how it will go down. The vendors simply need Intel. There is now way they will make enemies with them. The problems are simply passed on to the customers who have no other option but accept the reduced performance.
- flukus 9y agoMaybe we could develop in more efficient languages with more efficient frameworks so that all the pressure to improve performance doesn't land on the hardware side? Or we could say developer time is more important and keep pumping out electron apps, leaving intel to continue pushing the boundaries of physics.
- mikeash 9y agoThey had $4.5 billion in profit last quarter. If they want help, they can pay for it.
- newman8r 9y agoIf it's possible to get an eventual legal judgement against them, perhaps instead of paying x-billion dollars in fines, maybe they should be forced to make their future work open source.
- analognoise 9y ago1) They aren't going to have to pay a fine 2) This would just screw the shareholders, making the stock worth less 3) Open source doesn't have the people, skills, or finances to utilize Intel's internal design data - the only beneficiary from this would be other chip manufacturers and nation-states. I'm not sure who this would benefit?
- newman8r 9y agoI was thinking the benefit would be the ability to audit it, but yeah, not going to happen.
- colemannugent 9y agoWow. This is bad for Intel. Industry experts have been expressing concerns for this for ten years. Does this open Intel up to possible repercussions?
- alphaalpha101 9y agoWhen has any tech company ever had to face any sort of repercussions for bugs? I wholeheartedly think they should have to. But they don't.
- forapurpose 9y ago> Industry experts have been expressing concerns for this for ten years. AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. We can find endless criticisms of every major company from the last 10 years (including on HN!); picking this one mailing list posting is bit arbitrary in the context of these exploits, even if de Raadt makes some good general points.
- cat199 9y ago> AFAICT, de Raadt was concerned about Intel in general, but not the recent exploits in particular. Really? How do you explain the following: > These processors are buggy as hell, and some of these bugs don't just cause development/debugging problems, but will ASSUREDLY be exploitable from userland code. > Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us. > AI90 is exploitable on some operating systems (but not OpenBSD running default binaries). Plus huge development effort in stack/address randomization, W^X pages, dynamic kernel and c library relinking, etc as simply 'concern about intel in general' but not any details 'in particular'? Even if the stated position is not true, it would be logically inconsistent to assume someone whose operating system project focuses on 'security and correctness' to simply be making general statements and not being concerned with actual low-level details..
- cthalupa 9y agoWhat forapurpose said: > but not the recent exploits in particular What you said: > but not any details 'in particular'? Looking at the list of items Theo gave, most of them were fixed previously, and the others, at least to my largely uneducated eye, do not appear to be related to this specific issue. Unless I am mistaken (and that's certainly possible!) it was not at all related to Spectre/Meltdown
- forapurpose 9y agoAt least one of the recent exploits needs to be mitigated at the OS level (I haven't looked at the details carefully, but I know Microsoft and Linux are working on it). Is OpenBSD affected and if so, what are they doing to mitigate it?
- tedunangst 9y agoAffected and probably doing what everybody is doing for mitigation.
- forapurpose 9y ago> probably doing what everybody is doing for mitigation Is there any discussion? I thought OpenBSD development mostly took place on public mailing lists ?
- tedunangst 9y agoSome issues tend to attract a lot of lookie loos. The patch probably won't be improved by a dozen replies about the incompetence of intel.
- deleted 9y ago[deleted]
- forapurpose 9y agoI understand their need and priority, but sometimes those discussions are a great way to learn about the vulnerability - open development teaches others.
- tedunangst 9y agoI don't disagree. I prefer more open development and try to encourage it, but everyone has their own preferences for what to share.
- 9y ago
- jlgaddis 9y agoThis image is linked in the e-mail thread, with (some of?) the errata: https://www.geek.com/images/geeknews/2006Jan/core_duo_errata__2006_01_21__full.gif https://www.geek.com/images/geeknews/2006Jan/core_duo_errata... I'm just surprised that the URL is still valid after 12 years!
- userbinator 9y agoIs it just me or do AE4 and AE11 have the same description (REP MOVS crossing pages of different types) yet completely different classification/impact? IIRC this behaviour is now documented in the official manuals as "by design" since it was like that since the P3.
- deleted 9y ago[deleted]
- agumonkey 9y agosame, and don't bother reading too much, the best bugs came after ... incredible how I (we) ran on buggy hardware for so long. We should fund a tiny group for sane cpu design.
- alex_duf 9y agoThat would be great. I know nothing about low level programming, and I'm wondering if webassembly couldn't be a good place to start designing CPU instruction sets? Can someone more competent on the matter tell me if this idea is crazy?
- protomikron 9y ago> Can someone more competent on the matter tell me if this idea is crazy? Yes, it's crazy. :) But seriously, the ISA (instruction set architecture) is not the problem, but the optimizations (deep pipelines and speculative execution, etc.) are.
- alex_duf 9y ago
- nasredin 9y agoPrescient money quote: >As I said before, hiding in this list are 20-30 bugs that cannot be worked around by operating systems, and will be potentially exploitable. I would bet a lot of money that at least 2-3 of them are.
- thisisit 9y agoDupe? https://news.ycombinator.com/item?id=16071813 https://news.ycombinator.com/item?id=16071813
- alecco 9y agoYes, but as the mods didn't catch it now the conversation is here.
- paulhodge 9y agoIf only he had come up with a catchy name and a logo, we would have listened.
- buryat 9y agoRemember that naming is one of the hardest things in software engineering.
- mrep 9y agoThat and off by one errors ;)
- endymi0n 9y agoConcurrency You forgot 2) Cache invalidation and 3)
- mrep 9y agoHaha, you are correct, but there are some other hard problems that I now remember after some quick googling since i forgot all the related jokes :) There are only two hard problems in distributed systems: 2. Exactly-once delivery 1. Guaranteed order of messages 2. Exactly-once delivery There's two hard problems in computer science: we only have one joke and it's not funny. Source: https://martinfowler.com/bliki/TwoHardThings.html https://martinfowler.com/bliki/TwoHardThings.html
- tracker1 9y agoThe two most difficult things in software development. * naming things * cache invalidation * off by one errors
- taneq 9y agoIt's always worth having it stated in the canonical form. :)
- nmjohn 9y agoThe linked intel erata pdf file is 404'ing, but I think this [0] matches if you are curious about this line: > Note that some errata like AI65, AI79, AI43, AI39, AI90, AI99 scare the hell out of us. [0]: http://download.intel.com/design/processor/specupdt/313279.pdf http://download.intel.com/design/processor/specupdt/313279.p...
- buryat 9y agough, I checked some of them, and most of them suggest accessing protected memory. I believe that Intel didn't believe that these bugs suggest a fundamental issue that can be exploited, until Google Project Zero created a working exploit.
- deleted 9y ago[deleted]
- andrewstuart 9y agoThere's nothing prescient about saying that computer system X or Y can be exploited in ways yet to be discovered. The entire Internet is wide open, the holes just aren't known yet.
- chris_wot 9y agoYou miss the point. Theo wasn't just hand waving, he had identified specific issues that he believed would eventually get exploited.
- endorphone 9y ago"he had identified specific issues that he believed would eventually get exploited" But those aren't the issues that were exploited. His post has absolutely nothing to do with the current issues. It's just uninformed dogpiling (the ignorance of the crowd). All chips have errata. This post is not particularly informative or relevant to anything.
- mannykannot 9y agoThis is not the ignorance of the crowd, it is the insight of one informed individual. Dismissing as irrelevant all concerns except those that have already been exploited would be closer to being "the [self-inflicted] ignorance of the crowd" in these matters.
- endorphone 9y agoEveryone fishing around for anyone saying anything about Intel chips ever, and then trying to shoehorn it into a current narative is the ignorance of the crowd. Every single chip has errata. In this case Theo is pointing at Intel's own list of defects in a revision/chip, which is profoundly unilluminating, and is completely and absolutely irrelevant.
- mannykannot 9y ago
- siwatanejo 9y agoThere's one way to not be affected by these bugs: use an opensource OS along with opensource applications (no, proprietary apps even inside sandboxes don't count). EDIT: oh, and using the NoScript browser add-on :) To all the downvoters: please prove me wrong by replying ;)
- cthalupa 9y agoExcept that these bugs were all open on open source operating systems, as well... Do you think Linux wasn't affected by Spectre and Meltdown? That the BSDs aren't? That Xen isn't? Your comment is disingenuous and dangerous.
- ZiiS 9y agoI think their point is the exploit code would be obvious in open source applications and you could choose not to run them. Violates the defense in depth precaution.
- siwatanejo 9y agoYou're (and most likely all downvoters) completely missing the point. I never said that opensource software is not affected, I said "not being affected as a user". Because opensource software, being peer-reviewed, will never try to exploit a CPU bug. Opensource software is, by default, non-malicious.
- Dylan16807 9y ago> Opensource software is, by default, non-malicious. So is closed source software. You seem to be deeply confused about the scenarios people are worried about. The main ones are 1. untrusted users being hosted 2. javascript off the web. All the open source in the world doesn't help in either scenario. You're focused on someone deliberately running a malicious program. But if they do that, these exploits aren't even necessary to do severe harm. It's a marginal scenario at best.
- 9y ago
- ycmbntrthrwaway 9y agoSee also, Kris Kaspersky claimed he was able to exploit some of them in browsers back in 2008: https://news.ycombinator.com/item?id=16076941 https://news.ycombinator.com/item?id=16076941
- jimjimjonjon 9y agoLots of people with skin in the game here judging by some of the weirdly supportive of Intel comments there are, considering how much of a monumental fuck up this is.
- deleted 9y ago[deleted]
- dis-sys 9y agothis is a good reminder for everyone to stay away from from those engineering sample Xeon processors on ebay/taobao.
- jokoon 9y agoI know I will sound like a conspiracy theorist, but can those bugs be intentional? I mean if you are a security agency, would it be possible to push for the introduction of such bugs?
- Waterluvian 9y agoI think it's not unreasonable to think about the possibility of that. My understanding is that these bugs could have been exploited for a very very long time without being noticed? I also wonder if one or more security agencies find a lot of their efficacy in just a small handful of exploits. And if those were to be patched, they'd find themselves severely hamstrung. So seen as a threat to national security, they have a strong need to ensure the availability of exploits.
- pier25 9y agoPossible, but I think it's more probable that security agencies took advantage of those bugs with the help from Intel than intentionally putting those there in the first place.
- jerf 9y agoOccam's Razor suggests to me that intelligence agencies have not had to push for processor bugs, on the grounds that A: we can adequately explain the initial existence of these bugs by normal engineering, marketing, and management considerations such as almost everyone here has experienced personally and B: the field of the bugs that come from my first point is so ripe that the intelligence agencies are better served by examining them carefully and finding their own exploits. The primary reason for this is that the best hidden paper trail is the non-existent paper trail; by finding bugs independently and holding all knowledge within the agency, there is zero risk of it ever being revealed that they deliberately inserted bugs into the CPU, which would be a PR disaster for all concerned (and to a non-trivial extent, an act of war). Given that we know that intelligence agencies have asked for backdoors before, in both hardware and encryption standards, do not interpret my post here as a claim that they would never ever even think of asking for plausibly-deniable CPU bugs to be inserted into hardware. I am just saying that Occam's Razor says we should prefer the perfectly plausible scenario I gave above where they do not have direct involvement in these bugs, not because of their pristine ethics, but because given the circumstances on the ground, actively intervening is not their best choice from their point of view using their valuation function, when they can attain all their goals without active intervention. (I'm willing to believe in things that might be labelled "conspiracy theories"; history is rife with proof that they have existed in the past, such as the aforementioned cases where we know backdoors have been inserted into crypto standards, as well as other things such as the way in which the Soviet Union was created which essentially involved what was initially a small conspiracy, and I see no reason to believe they have ceased in the modern times. But I want to see how the conspiracy theory passes Occam's Razor; many of the conspiracy-minded, in my opinion, underestimate the randomness and everything-is-always-correlated-a-bit-ness of the real world.)
- danjoc 9y agoSince C2Ds are still highly regarded by the FSF RYF crowd, I wonder how much of this has been mitigated and how much of this is still an issue with LibreBoot Trisquel laptops.
- equalunique 9y agoFrom the email: "(While here, I would like to say that AMD is becoming less helpful day by day towards open source operating systems too, perhaps because their serious errata lists are growing rapidly too)." Glad to see that in 2018 AMD's reputation has generally improved from this.