3 ms·
Why you single intel on this, ARM and POWER also affected https://www.ibm.com/blogs/psirt/potential-impact-processors-power-family/ https://www.ibm.com/blogs/p
by alsadi 9y ago
Why you single intel on this, ARM and POWER also affected
https://www.ibm.com/blogs/psirt/potential-impact-processors-power-family/ https://www.ibm.com/blogs/psirt/potential-impact-processors-...
- roblabla 9y agoEveryone is affected by Spectre, but my understanding is that Meltdown is a particularly powerful "version" of Spectre that only affects Intel CPUs ?
- K0nserv 9y agoHaving just read the Meltdown paper, but not the Spectre paper. My understanding is that yes Meltdown is much easier to exploit and more powerful. I believe Spectre requires the attacker to consistently fool the branch predictor while Meltdown enables reading kernel memory mapped into user space process via access in speculatively executed code and observing the affects on the CPU cache.
- mnw21cam 9y agoSpectre involves finding some code in the kernel that has access to the data, and getting it to access it speculatively before the conditional that tells it not to is evaluated. Meltdown involves crafting some code yourself that speculatively accesses data it does not have access to before the CPU rejects the access due to permissions. In other words, Meltdown involves your code accessing the data, but Spectre involves getting the kernel to do it for you. Spectre is a neat clever side-channel attack that is hard to protect against, while Meltdown is a blundering error in the way the CPU works.
- alsadi 9y agofrom what I understand AMD and ARM are also affected by the toy POC, quote Out-of-order execution is an indispensable performance feature and present in a wide range of modern processors. quote However, for both ARM and AMD, the toy example as described in Section 3 works reliably, indicating that out-of-order execution generally occurs and instructions past illegal memory accesses are also performed end of quote it just need more work to make it work their https://meltdownattack.com/meltdown.pdf https://meltdownattack.com/meltdown.pdf
- K0nserv 9y agoI saw some speculation that AMD might raise the kernel memory read exception earlier than Intel which prevents any subsequent instructions from using the value fetched from the kernel address space.
- Fnoord 9y agoMy ELI5 attempt: There are 3 vulnerabilities. Meltdown is 1 of the 3. Meltdown is pretty much Intel only. Some ARM SoCs are also affected, but these are relatively rare. AMD64 is unaffected by Meltdown. Spectre are the other 2 vulnerabilities. Spectre affects pretty much everyone. Meltdown is more severe, and more of a blunder. For a technical explanation, see [1]. Was recently referred to at HN as well. [1] https://www.raspberrypi.org/blog/why-raspberry-pi-isnt-vulnerable-to-spectre-or-meltdown/ https://www.raspberrypi.org/blog/why-raspberry-pi-isnt-vulne...
- K0nserv 9y agoDo you have any source on why AMD64 is unaffected? The paper only mentions that they couldn't make their current approach work on AMD, but it doesn't rule out that it could be improved and made work
- betterunix2 9y agoAMD's microarchitecture does not perform speculative loads that would cause a segfault, according to this AMD engineer: https://lkml.org/lkml/2017/12/27/2 https://lkml.org/lkml/2017/12/27/2
- deleted 9y ago[deleted]
- K0nserv 9y ago> We also tried to reproduce the Meltdown bug on several ARM and AMD CPUs. However, we did not manage to successfully leak kernel memory with the attack de- scribed in Section 5, neither on ARM nor on AMD. The reasons for this can be manifold. First of all, our im- plementation might simply be too slow and a more opti- mized version might succeed. For instance, a more shal- low out-of-order execution pipeline could tip the race condition towards against the data leakage. Similarly, if the processor lacks certain features, e.g., no re-order buffer, our current implementation might not be able to leak data. However, for both ARM and AMD, the toy example as described in Section 3 works reliably, indi- cating that out-of-order execution generally occurs and instructions past illegal memory accesses are also per- formed. From the Meltdown paper[0] section 6.4 it would seem that out of order execution referencing illegal memory locations still occurs unless of course I'm misunderstanding something. 0: https://meltdownattack.com/meltdown.pdf https://meltdownattack.com/meltdown.pdf
- mnw21cam 9y agoIn terms of ARM, only some of the ARM CPUs are affected. The CPUs used in the Raspberry Pi range don't have out of order execution, so aren't affected.