4 ms·
HN really needs a sticky feature for comments concerning security patches and other updates that can bork your machine. In this case, someone who dreams in har
by phantom_oracle 9y ago
HN really needs a sticky feature for comments concerning security patches and other updates that can bork your machine.
In this case, someone who dreams in hardware, breathes ASM and talks in bytes, needs to clearly inform the community here concerning these questions:
- SHOULD THIS MICROCODE UPDATE BE PERFORMED SEPARATELY FROM RUNNING: apt-get update && apt-get upgrade ?
- WHAT IS THE IDEAL/BEST WAY TO PERFORM THIS MICROCODE UPDATE?
- djsumdog 9y agoI say it'd always best practice to update things via the standard package manager. I'm sure debain/RHEL/cent repos already have updated kernels for the PTI fix. Unless you are seriously hitting hard performance issues with the new kernels (there's nothing in the firmware page that says if this is for Meltdown or Spectre, or did I miss it?), wait for your distribution to update its linux-firmware package. People on the unstable branches will get to test it first and give appropriate feedback before it gets marked stable, and there will also most likely be a delay before a kernel is released that re-enabled PTI (once again, if this is a PTI/Meltdown fix).
- pasbesoin 9y agoI like how HN's adherence to a certain simplicity has, I think, helped keep the community integrated, and relatively egalitarian and respectful (with a lot of other work going into that, as well, I'm sure). But there have been a few times, this year and recently, where very pertinent security issues have had threads of both immediate and enduring value, with information -- mostly in the comments -- both useful and not available elsewhere that I've seen, online. Maybe another one of HN's select, few categories. E.g. "essential". Probably populated solely at the moderators' discretion. In that, I'm in favor of the benevolent dictators model: Maybe some polite and well-argued comments about what might belong, but no voting or manipulable -- technically nor socially -- as to what gets in there. When a processor, platform, OS is significantly borked, and the knowledge is essential to a broad portion of this community. That would be what goes in there. Starts as regular threads. If the need to know and value of them are high enough, they get tagged with that category. So that, e.g. I can more readily find that Intel Management Engine thread a couple of months later, when I'm deciding whether I want to patch (or patch further) and what mitigations to keep in place. I don't know, and maybe I'm wrong. Just an idea. P.S. I don't know whether the front page would link "essential" somewhere, or whether it would be like some other qualifiers, that don't have a front page presence. Again, the simplicity of the front page, versus the value of the information and the need to know. P.P.S. I really am afraid, though, of the arguments its presence might engender, as to what belongs in it, and the disharmony this might introduce and foster. There's a LOT of value to the existing simplicity (of the interface, if not always the elephant behind it).
- snowwindwaves 9y agoYou can make this page! Start curating HN posts and comments and the other resources relative to your essential needs and see what magic falls out
- noobermin 9y agoWhile I understand your sentiment, probably the best action is to do the default, which is to wait for an update from your package manager/OS. The news on HN is, well news, so it's often fresh and breaking news. Acting on said news entails its own risks unless you know what you're doing, and there aren't ambiguities which may bork your computer.
- stephenr 9y agoOn debian at least microcode updates arent included by default you have to install the appropriate package (intel vs amd)
- navinsylvester 9y ago# Download new release of microcode from https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File https://downloadcenter.intel.com/download/27431/Linux-Proces... # Copy intel-ucode directory to /lib/firmware # echo 1 > /sys/devices/system/cpu/microcode/reload # update-initramfs -u # Reboot Also check - https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAn...
- pvg 9y agoNo it doesn't, since that kind of thing is not what HN is for and there are many places that are. It does need fewer people typing breathlessly in all caps a lot.