3 ms·
Apart from usual 'open source' and 'who controls the software' dogma, I find his endless gnawing about libreboot and Intel ME very related to general closed-box
by binaryapparatus 9y ago
Apart from usual 'open source' and 'who controls the software' dogma, I find his endless gnawing about libreboot and Intel ME very related to general closed-box-that-we-trust problems. Trouble is now I think he wasn't paranoid enough.
- jraph 9y agoSo I sent those quotes to Richard Stallman: - https://news.ycombinator.com/item?id=16081602 https://news.ycombinator.com/item?id=16081602 (this thread's original message) - https://news.ycombinator.com/item?id=16081712 https://news.ycombinator.com/item?id=16081712 (the parent) - https://news.ycombinator.com/item?id=16081700 https://news.ycombinator.com/item?id=16081700 ("Stallman is the hero we don’t deserve") With some encouraging sentences to keep on making the world a better place. He felt honored. He asked me to post this for him. "Now that you recognize these problems are real, how about joining in the work to fix them? See gnu.org/help for a list of many different kinds of work that we need (programming is just one of many), then pick one and help!"
- matthewmacleod 9y agoThat’s a different issue. An important one, I agree, but kind of orthogonal to the introduction of a hardware bug, which could equally happen in an open architecture.
- binaryapparatus 9y agoWhat initially reminded me of him is the way he uses internet. That seems more and more appealing from this perspective.
- ealexhudson 9y agoHis "origin story" for free software relates to a printer, and being unable to see the code (I think the driver rather than the firmware). His whole point is that software can be changed, and if only a vendor can touch the software for hardware you've purchased then you're entirely beholden to them. Of course on some occasions the software isn't going to be able to compensate, but Stallman's ideas about why free software is important are grounded in some very practical realities.
- mitchty 9y agoHaving the source for anything in the cpu here won't help when the architecture design itself is at issue. If you have to respin new silicon, all the software in the world won't help you. Ever see a wire on pcb boards going from one end of the board to another? Thats the hardware equivalent of a: "we can't fix this properly, but we can hack a fix on until we can fix it right in the next revision" hack.
- BuildTheRobots 9y agoWithout wanting to side track the the conversation too much, I'm guessing I'm right in my assumption that implementing x86 cores on an FPGA (so we can add wire traces to the cpu after the fact) is still way to slow and expensive to even be close to a reality?
- monocasa 9y agoYeah, for something like a modern x86 core, you'd need something like this. https://www.cadence.com/content/cadence-www/global/en_US/home/tools/system-design-and-verification/acceleration-and-emulation/palladium-z1.html https://www.cadence.com/content/cadence-www/global/en_US/hom... It'll cost you ~$1M and run at a few MHz.
- mitchty 9y agoCorrect, FPGA simulation of a 3.0Ghz processor means you'd be waiting on the order of weeks to boot into linux. I work for a company that works with Intel on new things. Lets just say the FPGA's they use are... really expensive, and despite being capable of simulating a design fast, are still very slow. By expensive I found out $20 million per FPGA simulator was on the low end. And I think that would simulate at the rate of about 10mhz for the amount of transistors/internal setup present. Fpgas are cool, but a poor choice for fixing this issue. You could probably do it for up to an 80386 with some $400ish dollar FPGA's.
- BuildTheRobots 9y ago
- bitwize 9y agoFor RMS, one does not simply browse a Web page. He has wget fetch the page and then email it to himself, where he looks at it in Emacs. Given that Spectre is trivially exploitable from motherfucking JavaScript, this bit of craziness turns out to have concealed much wisdom.