5 ms·
Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws?
by linohh 9y ago
Has HN begun to collect suggestions to intel how to handle the situation and what to change regarding community interaction to reduce the impact of such flaws? Instead of bashing our heads out, maybe it's time to offer them a hand when they're down on the ground.
- rdtsc 9y agoI am sure Intel will be fine. It is effectively a monopoly in the desktop and server market and enjoyed their position and profits for years. They can handle a bit of criticism from a bunch of nerds on HN. Maybe loading data speculatively across a protection boundary was careless. It seems besides the latest ARM CPUs no other vendor went that route. But not owning up to it and issuing PR statements saying "This works as designed, not a bug" is a bit hard to stomach. But if it needs help drafting a better PR release, someone is welcome to point them to HN's comments section.
- busterarm 9y agoA friend of mine "bought the dip" and profited about $100 in the first 20 seconds and it only got better as the day progressed.
- 013a 9y agoIf they need help, they should look at Google's release. Despite effectively saying the same thing, Intel's is disgusting and defensive, like a guilty man in a police interview yelling "I didn't do it!" Google's is facts, no bullshit language, and effective.
- JdeBP 9y agoLike so. * http://www.theregister.co.uk/2018/01/04/intel_meltdown_spectre_bugs_the_registers_annotations/ http://www.theregister.co.uk/2018/01/04/intel_meltdown_spect... https://news.ycombinator.com/item?id=16064545 https://news.ycombinator.com/item?id=16064545 (https://newsroom.intel.com/news/intel-responds-to-security-research-findings/ https://newsroom.intel.com/news/intel-responds-to-security-r...) * https://news.ycombinator.com/item?id=16072368 https://news.ycombinator.com/item?id=16072368 (https://newsroom.intel.com/news-releases/intel-issues-updates-protect-systems-security-exploits/ https://newsroom.intel.com/news-releases/intel-issues-update...) * https://news.ycombinator.com/item?id=16067245 https://news.ycombinator.com/item?id=16067245 (https://www.amd.com/en/corporate/speculative-execution https://www.amd.com/en/corporate/speculative-execution) * https://news.ycombinator.com/item?id=16068118 https://news.ycombinator.com/item?id=16068118 (https://developer.arm.com/support/security-update https://developer.arm.com/support/security-update) * https://news.ycombinator.com/item?id=16072912 https://news.ycombinator.com/item?id=16072912 (http://blog.dustinkirkland.com/2018/01/ubuntu-updates-for-meltdown-spectre.html http://blog.dustinkirkland.com/2018/01/ubuntu-updates-for-me...) * https://news.ycombinator.com/item?id=16071769 https://news.ycombinator.com/item?id=16071769 (https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAn...) * No headline, although mentioned at https://news.ycombinator.com/item?id=16074531 https://news.ycombinator.com/item?id=16074531 and elsewhere (https://www.freebsd.org/news/newsflash.html#event20180104:01 https://www.freebsd.org/news/newsflash.html#event20180104:01) * https://news.ycombinator.com/item?id=16076660 https://news.ycombinator.com/item?id=16076660 (https://support.microsoft.com/en-gb/help/4072699/important-information-regarding-the-windows-security-updates-released https://support.microsoft.com/en-gb/help/4072699/important-i... https://support.microsoft.com/en-gb/help/4072698/windows-server-guidance-to-protect-against-the-speculative-execution https://support.microsoft.com/en-gb/help/4072698/windows-ser... ) * https://news.ycombinator.com/item?id=16075348 https://news.ycombinator.com/item?id=16075348 (https://support.apple.com/en-gb/HT208394 https://support.apple.com/en-gb/HT208394) * https://news.ycombinator.com/item?id=16076175 https://news.ycombinator.com/item?id=16076175 (https://lists.debian.org/debian-security-announce/2018/msg00000.html https://lists.debian.org/debian-security-announce/2018/msg00...) * https://news.ycombinator.com/item?id=16076328 https://news.ycombinator.com/item?id=16076328 (https://lists.opensuse.org/opensuse-updates/2018-01/msg00000.html https://lists.opensuse.org/opensuse-updates/2018-01/msg00000...)
- wasx 9y ago>They can a handle a bit of criticism from a bunch of nerds on HN. What a reductive and shortsighted evaluation of the situation. Can they handle the loss of faith from big companies? Can they handle the loss of faith from the entire tech community? Seems to me that AMD et al have now got the perfect opportunity to erode intels market share and build up a large market base amongst cloud providers etc (not to mention security minded users) that require technology that is both resistant to meltdown and not underperforming hardware. It's silly to act like this is a storm in a teacup because the HN community is up in arms over it. Monopolies fall, and the loss of trust and key clients tends to precipitate that fall. >But if it needs help drafting a better PR release, someone is welcome to point them to HN's comments section. Their PR was shocking, but on the order of things people are upset about over this incident, this is literally at the bottom.
- rdtsc 9y ago> They can a handle a bit of criticism from a bunch of nerds on HN. It was a tongue-in-cheek response to OPs statement that we should feel bad for Intel and offer it help. I suggested that it needs help drafting a better PR release that's a bit more honest and straightforward. > Can they handle the loss of faith from big companies? With a $200B capitalization they certainly can. > Seems to me that AMD et al have now got the perfect opportunity to erode Agreed. The next step is to see if any of the large cloud providers or PC manufacturers will announce they are buying AMD CPUs. I hope because I'd like to be able to buy cheaper CPUs and have more competitors in the market. But realistically I kind of doubt it. At the end of the day INTC's stock hasn't moved that much. The performance hit as reported by Google didn't seem to as big.
- cat199 9y ago> At the end of the day INTC's stock hasn't moved that much. nor should it.. huge stock (so less speculators), many products besides x86 PC processors, and their reaction/fix to this & subsequent impact to actual earnings hasn't shaken out.. not pro or against intel. but mentioning this as concerns market stuffs.
- user5994461 9y ago
- RachelF 9y agoThe Register did a great analysis of turning the Intel Press release into English. "We translated Intel's attempt to spin its way out of CPU security bug PR nightmare as Linus Torvalds lets rip on Chipzilla" https://www.theregister.co.uk/2018/01/04/intel_meltdown_spectre_bugs_the_registers_annotations/ https://www.theregister.co.uk/2018/01/04/intel_meltdown_spec...
- baldfat 9y ago> It is effectively a monopoly in the desktop and server market But it couldn't be better timing for ARM. AMD isn't the competition (Though this helps them a little bit) it really is all about ARM and it is going to get a lot more attension with this. Windows runs on ARM now. CPUs can't get much smaller. It is now how many cores and thermal control you can place on a waffer. ARM has the advantage in both of those. We just have to learn how to utilize multiple cores better than we are now.
- foobiekr 9y agoWhich ARM? Have you ever even looked at ARM implementation errata? At the errata for people doing semi-custom ARM like Cavium? Do you think that those companies are as diligent as Intel? I can’t say anything about ARM vendors, but I’m pretty familiar with MIPS and PowerPC errata from chips in the mid-2000s and they generally made Intel look 10x as professional and careful.
- mannykannot 9y agoSaying "it is not a flaw, it is working as designed", when that design has led to a demonstrated exploit, marks one as either clueless or duplicitous. Why would a company as large as Intel choose to present itself as such? I guess it thinks we are too dumb to notice (Intel did say it is not a flaw in its press release; I don't know whether it explicitly tried the "working as designed" excuse, but the no-flaw claim by itself is nonsense, regardless.)
- rdtsc 9y agoMy guess is that the memo, besides the marketing channels was also filtered through the legal department and they advised not to admit guilt as they probably expect to be sued at some point. Then a clear admission on their part would be slam dunk.
- mannykannot 9y agoThat is probably so, though if it came to being sued, I guess the plaintiffs' counsel would be ready to point out the flaws in that line of thinking. On the other hand, Intel's stock price did recover in response, reversing the somewhat panicked or speculative drop earlier in the day, so perhaps this was mainly for the market.
- colemannugent 9y agoIMO the first step would be disclosing all their tricks they implement outside of the specs they give. If researchers had adequate documentation of all the side effects that these tricks introduce then it could be properly audited.
- randomString1 9y agoLooking at how they behave the only thing I would expect from them is to not give free shovels when people are trying to dig. They will keep turtling until there's a new product they can push and rush everybody to ditch the "insecure predecessors".
- tedunangst 9y agoSomething like adding "Implicit caching occurs when a memory element is made potentially cacheable, although the element may never have been accessed in the normal von Neumann sequence. Implicit caching occurs on the P6 and more recent processor families due to aggressive prefetching, branch prediction, and TLB miss handling." to the developer's manual.
- xvilka 9y agoAfter all the history of shady things with Intel ME/AMT, hindering coreboot projects efforts, etc I highly doubt there will be people who want to do that. Hopefully this story will start a big change in Intel policies (more likely it is not though).
- jlgaddis 9y ago(playing devil's advocate here, to be clear) What leads you to believe that Intel has any reason to think that there's an issue that needs changed? Or that "the community" knows anything about their business processes or what Intel should do? They have their highly-paid C-levels to figure that out. From their perspective, there's no problem. Nothing needs fixin'. You'll keep buying their CPUs, anyways -- you don't really have much of a choice, do you? [0] Just go install those updates from your vendor(s) and go about your business, you'll be fine. No big deal, nothing to worry about. Carry on. Just like you did with that recent little ME/AMT issue. There'll be another issue to deal with in a few days and everyone will forget all about this one. [0]: Oh, you're gonna replace all your infrastructure with AMD's CPUs, huh? Yeah, sure you are. They're no different.
- vbezhenar 9y agoBasically buying new Intel processor to replace old will yield 5-60% performance in I/O-heavy workloads even without any other changes but fixed processor bug, unless you're ready to tweak with your OS settings and fine with potential vulnerability. With proper marketing they can make huge profits from this situation. Sure, you can buy AMD, but Intel is still faster for many benchmarks. Given that they knew about bug for 7 months, I think that soon new processors will be without Meltdown bug.
- mindentropy 9y agoYou are right in your assessment. This is how it will go down. The vendors simply need Intel. There is now way they will make enemies with them. The problems are simply passed on to the customers who have no other option but accept the reduced performance.
- flukus 9y agoMaybe we could develop in more efficient languages with more efficient frameworks so that all the pressure to improve performance doesn't land on the hardware side? Or we could say developer time is more important and keep pumping out electron apps, leaving intel to continue pushing the boundaries of physics.
- mikeash 9y agoThey had $4.5 billion in profit last quarter. If they want help, they can pay for it.
- newman8r 9y agoIf it's possible to get an eventual legal judgement against them, perhaps instead of paying x-billion dollars in fines, maybe they should be forced to make their future work open source.
- analognoise 9y ago1) They aren't going to have to pay a fine 2) This would just screw the shareholders, making the stock worth less 3) Open source doesn't have the people, skills, or finances to utilize Intel's internal design data - the only beneficiary from this would be other chip manufacturers and nation-states. I'm not sure who this would benefit?
- newman8r 9y agoI was thinking the benefit would be the ability to audit it, but yeah, not going to happen.