5 ms·
Meltdown and Spectre have opened up new hacking threats, sparked class actions, and enraged longtime partners. At this point in time, it is known that Intel is
by xtrapolate 9y ago
Meltdown and Spectre have opened up new hacking threats, sparked class actions, and enraged longtime partners.
At this point in time, it is known that Intel isn't the only vendor producing hardware susceptible to Meltdown and Spectre, which is another of saying AMD is in the same boat. Given this fact, I'm struggling to understand why Intel is being continuously singled out.
Meltdown and Spectre aren't the first, won't be the last. I personally feel that a more interesting discussion should take place: how to prepare/plan-for/deal-with similar issues further down the road. One particular thought that comes to mind is that this industry lacks an effective recall mechanism.
- HugoDaniel 9y agoWell they arguably set the road for others to pave. They are a very big player and their (bad) design decisions gradually got adoption among the other players. Is AMD affected by Meltdown ? Do you know something that we don't ?
- jacoblambda 9y agoAs far as I'm aware, Intel is the only vendor susceptible to Meltdown.
- johnbellone 9y agoThere are some ARM CPU that are also vulnerable to Meltdown[0]. https://support.apple.com/en-us/HT208394 https://support.apple.com/en-us/HT208394
- chapill 9y agohttps://developer.arm.com/support/security-update https://developer.arm.com/support/security-update A75 is meltdown. Qualcomm Snapdragon 845. Go ahead and skip the next generation of Android flagships. The whole line of them will be based on 845 garbage.
- xigency 9y agoMeltdown is an Intel-specific design mistake dating back a decade. It is also the bigger fish. Spectre, while real, has been a gift to Intel to use as a smokescreen in PR and reporting.
- wsxcde 9y agoBut that is what it is, a design mistake -- a totally non-obvious design mistake. I believe the number of people who would have looked at Intel's design decisions related to meltdown and thought to themselves this was a credible security holeis very close to zero. I can say this with some confidence because I used to do processor performance modeling for AMD, security verification for Intel and now do research in hardware security verification. This is not a bug until you look at the exploit. I am certain AMD/ARM/RISC-V or whatever other Intel competitor you can think of have similar security bugs in them. It's just a question of whether people will find them. In fact, knowing what I know about AMD and Intel, I'm willing to bet these other companies have more security holes, not less than Intel
- xigency 9y agoPerforming even speculative operations on protected memory is a mistake. Part of the speculation should be to check the protection before performing operations on the data. This _flaw_ is precisely why protected information is leaked via side-channel in the Meltdown attack. They decided on this design without realizing it was a mistake -- but that is exactly what it is. Same as Takata's airbag design which used an unstable compound. They were not unaware of the chemical propties of their inflating device. Instead, they miscalculated the impact.
- wsxcde 9y ago> Performing even speculative operations on protected memory is a mistake. Every high performance processor in the world performs speculative cache updates. That did not cause meltdown, nor did it cause spectre.
- throwaway203937 9y ago