3 ms·
Intel's PR dept is in overdrive, but the truth about this vulnerability is that it's essentially worst-case. It really only affects workloads where high perfor
by forgotpw2018 9y ago
Intel's PR dept is in overdrive, but the truth about this vulnerability is that it's essentially worst-case.
It really only affects workloads where high performance is important. The average user might not see an impact but if you need fast IO God help you. The solution is to 'make less syscalls' but the problem is that syscalls have always been slow and the people making a lot of them are only doing so because they absolutely have to
- Waterluvian 9y agoIsn't that like saying that it turns out this car we sold can only do 150, not 200. But it's okay because most of you never drive above 80 anyways. You're right. Most people who just surf the Netflix and download the YouTubes will not notice. But it's still a form of fraud, even to those who never max out CPU. I think fraud is a strong word knowing that this wasn't intentional. But they sold a lesser product than they advertised and need to make customers whole. Otherwise it pretty much is fraud.
- deleted 9y ago[deleted]
- mistercow 9y agoIs that remotely feasible? You're basically suggesting that Intel needs to refund or replace every PC and server CPU they've sold in the last five years. The fdiv recall cost Intel almost half a billion dollars, and that was for a small subset of processors that most people didn't replace. Intel has a lot of assets, but replacing five years worth of CPUs might actually bankrupt them.
- forgotpw2018 9y agoI deleted that because I thought it was too flamey after reading it again, but yeah refunding everyone is unrealistic. Maybe just average out the performance impact across large cloud providers and offer that as a percentage? It probably wouldn't be hard for a company like Google to crunch metrics before/after the update and give a number for how much their performance has been affected
- mistercow 9y agoYeah, I think it's clear that some amount of risk has to be absorbed by the public. It sucks, but it's in our best interest to keep pushing computing forward. And we should keep in mind that it's also not like these attacks are obvious. They took security researchers four years to find. I think the important thing here is precedent, rather than making customers whole. The question then is what, if anything, could Intel have done to anticipate and prevent this, and how do we incentivize them to take those measures in the future? It's also possible that there's nothing to change here. There's always going to be some risk, and trying to force that risk closer and closer to zero will at some point not be worth the tradeoff. As bad as this is, if the caution necessary to prevent it would have resulted in processors being half as fast as they are today anyway, there wouldn't be any point.
- anonacct37 9y agoI think people are underestimating how bad webapps are. I do... a lot of computing and by far the most CPU intensive applications on my computer are webviews. Either Gmail in chrome or slack. I'm actually going to be upgrading my laptop soon because slack+3 organizations crushes my laptop. Do you think browser vendors have been pushing JIT research forward, investing in webasm, and building things like servo because websites are so fast and light on CPU?
- djsumdog 9y agoI wonder if we'll start seeing more userspace storage drivers because of this. If anything, for big shops like this one, I wouldn't be surprised if we saw a move away from hosted providers (the "cloud" .. god I still hate it when people use that word), and return to co-located setups. At least for people who need immediately performance needs, AMD might make a lot of short term sales right now.
- walshemj 9y agowill be interesting to see the trend in sales of threadripper an eypc