6 ms·
This is all getting rather silly, right? I was the first one to mock Richard Stallman for being too radical, dramatic and paranoid but I can now confirm he wasn
by binaryapparatus 9y ago
This is all getting rather silly, right? I was the first one to mock Richard Stallman for being too radical, dramatic and paranoid but I can now confirm he wasn't. Every word he said in last 15 or so years is true.
This all simply makes all our IT related work just kids playing make-pretend security.
I am literally trying to figure out what other processors exist that can be used in everyday BSD/Linux work. Sparc? Some ARM branch? Any suggestions welcome.
- ThinkBeat 9y agoCame here to say the same thing. Richard Stallman was right and I wish we would learn to listen but I doubt that will happen.
- sp332 9y agoThis problem was discoverable for the last 20 years. Of all the confidential tech that goes into a CPU, this wasn't it.
- smacktoward 9y agoSo the question becomes, why didn't anyone discover it?
- usrusr 9y agoToo good to be shared perhaps? I don't like this conspiracy theory way of thinking, but post-Snowden it's difficult to draw a line.
- SAI_Peregrinus 9y agoBecause it's difficult. Sure, it's obvious in hindsight, but it's a flaw in a small part of a very large and complex system.
- pkaye 9y agoWhat happened to all the theorem proving software that are supposed to absolutely guarantee correctness of code. I guess they are only as accurate as the assumptions input into them?
- zlynx 9y agoIn this case the CPU does function exactly as designed. Any correctness prover would agree. It does show the problem of all theorem provers: they are only as good as the specification.
- SAI_Peregrinus 9y agoThe code conforms to the specification. It's not buggy. The specification does not conform to the user's expectations or documentation. It's flawed. Theorem provers can only prove that the code conforms to the specification, not to the user's expectations or documentation. They can be very helpful, but they aren't magic and can't interpret non-formal specifications.
- matthewmacleod 9y agoWhat specifically has Stallman said that relates to this particular issue?
- stuaxo 9y agoI guess along the lines that closed source "security" is an oxymoron.
- matthewmacleod 9y agoThat’s true to some extent, but it’s not like open source software is free from security issues. Open source might make it easier to find and fix issues, but it can’t avoid them entirely.
- SAI_Peregrinus 9y agoOpen source is necessary but not sufficient for security. Secure systems are a strict subset of open systems.
- binaryapparatus 9y agoApart from usual 'open source' and 'who controls the software' dogma, I find his endless gnawing about libreboot and Intel ME very related to general closed-box-that-we-trust problems. Trouble is now I think he wasn't paranoid enough.
- jraph 9y agoSo I sent those quotes to Richard Stallman: - https://news.ycombinator.com/item?id=16081602 https://news.ycombinator.com/item?id=16081602 (this thread's original message) - https://news.ycombinator.com/item?id=16081712 https://news.ycombinator.com/item?id=16081712 (the parent) - https://news.ycombinator.com/item?id=16081700 https://news.ycombinator.com/item?id=16081700 ("Stallman is the hero we don’t deserve") With some encouraging sentences to keep on making the world a better place. He felt honored. He asked me to post this for him. "Now that you recognize these problems are real, how about joining in the work to fix them? See gnu.org/help for a list of many different kinds of work that we need (programming is just one of many), then pick one and help!"
- tzahola 9y agoStallman is the hero we don’t deserve.
- deleted 9y ago[deleted]
- OldSchoolJohnny 9y agoA guy living in a cardboard box in an alley rambling on is just as likely to hit upon a semblance of relevance from time to time. Doesn't make them any less of a nutjob or any more worth listening to.
- mindcrime 9y agoThat's not really relevant though. rms is not "some nutjob living in a cardboard box" and his thoughts have proven to be extremely prescient and insightful over and over again. He's definitely "worth listening to" even if you don't agree with him on every single point.
- B1FF_PSUVM 9y agoThat was a barrel, actually. Bastard had the nerve to tell Alexander to "stand a little out of my sun." Total nutjob. No respect for wealth and power whatsoever.
- CamperBob2 9y agoI agree, in principle, but when the nutjob in question correctly predicts a dozen things in a row with no misses, you have to wonder if you might be missing something important.
- dmytroi 9y agoBeing free (or open) source have nothing to do with security: Linux/BSD still have 0day rootkits, yet all source is available, modern JS software have all tracking in the world, yet all source is available (VSCode telemetry). Even RISC-V, being fully open, most likely will be susceptible to spectre attack. Instead of false promises we need to develop better engineering: verification, computational math, etc. And also laws - no free/open license in the world will stop companies from tracking, but fine as big as 4% of total revenue (EU GDPR) will make them oblige.
- worblux 9y agoRISC V is certainly not vulnerable to Spectere as all the the real-world chips are in-order execution, meaning post-branch instruction never happen until after the branch is decided. Out of order variants are still in the design stage, so they may come up with a way to isolate or invalidate speculation effects on branch misprediction.
- solarkraft 9y agoOSS makes vulnerabilities easier to discover, but if the project isn't well known they may still easily go unnoticed.
- deleted 9y ago[deleted]
- rcoveson 9y agoIt seems like in the case of Meltdown and Spectre, FOSS may have /everything/ to do with security. FOSS with the addendum that you don't execute arbitrary javascript, anyway. In a world where personal computers only ran code the user could safely trust, these exploits would only be full attack vectors when applied to multi-tenant computing environments. I'm not arguing that FOSS systems are inherently more secure than closed systems, but when it comes to exploits that require arbitrary code execution to be effective, Stallman really was/is right. Between a NoScript browser extension and a system whose source code is entirely available to you, you've basically got Meltdown/Spectre immunity.
- 9y ago
- pkaye 9y agoTo be absolutely safe, you just need a processor that is simple enough not to use any of these performance enhancing techniques (ie out-of-order execution, speculation, branch prediction, caching.) Of course it might be much slower than you are used to but if security is your primary concern it makes sense.
- AstralStorm 9y agoOnly caching use a problem. Indirect branch prediction can be "flattened" at a cost by checking TLB in context switch, presuming the kernel sets it up nicely per process. The other techniques are fine. As usual, secure code needs to be written with timing attacks in mind and they don't change much there.
- userbinator 9y agoIronically enough, RMS could probably be using the most side-channel-leaking CPU on his computer and it wouldn't matter... because he is the sole user and runs only his carefully-chosen free software on it. His thoughts on cloud computing, however, are very much worth listening to.
- AstralStorm 9y agoBugs happen. I wouldn't even beyond emacs to not still have a remotely exploitable security issue. Not to mention Firefox.
- userbinator 9y agoHe is quite unusual in his habits, but considering that he is probably a more high-value target than the majority of us, I'd say his approach has served him well. https://stallman.org/stallman-computing.html https://stallman.org/stallman-computing.html Scroll down to the point titled "I am careful in how I use the Internet."
- dingo_bat 9y agoHow is Stallman more high-value than a software developer working in a tech company? I'd say the opposite is true.
- rcoveson 9y agoI don't think that was the point of the parent comment. Obviously Stallman's system is not perfectly secure, but it may well be immune to exploits that require arbitrary code execution like Meltdown and Spectre.
- cc439 9y agoIIRC, first generation Intel Atom CPUs are safe from Spectre due to their nature of being an in-order execution design. Those are the most modern/powerful in-order chips I can think of and now I regret selling the old Dell netbook I had in college.
- mikestew 9y agoI still have my old MSI Wind U100 from 2010-ish. I was lately wondering what to do with it. It’s already running Mint, so I guess I’ll make it my main machine. :-)
- djsumdog 9y agoStallman's argument is a good one against the Intel ME issues, but I don't think it apples to Meltdown. This is a specific side-channel attack in a super complicated system. Even if we had OSS x86/64 processors, this more similar to the protocol issues found in openssl.