5 ms·
I'm oddly lucky that I based my fanless server off an old Atom platform.
by avuton 8y ago
I'm oddly lucky that I based my fanless server off an old Atom platform.
- close04 8y ago"Luckily" most old Atoms will never get mitigations for Meltdown/Spectre :). So if you're using an Intel CPU today you'll just have to pick your poison.
- avuton 8y agoI was under the impression that they weren't susceptible.
- zzzcpan 8y agoSo, old Atoms are the only ones still usable intel systems and not vulnerable to Meltdown/Spectre/ME.
- namibj 8y agoNo, the Xeon Phi "accelerators" are usable too, they are basically 486 cores on modern litography (to allow for higher density/clock speeds), with a vector unit attached to them. I don't know how hard it would be to boot linux on one though...
- deleted 8y ago[deleted]
- detaro 8y agoOnly the first generation (X100 model numbers). If I remember right they ship with Linux already, but need a host system to run in of course.
- namibj 8y agoThis host system should be not much more than a PCIe root emulator though. This is the level one can get on an e.g. FPGA with custom logic, which implies that any attempts to insert hardware/firmware level attacks into the actual logic you care about is near impossible to do due to the low-level nature of the custom PCIe implementation.
- bobdole12345 8y agoThey already run linux as their firmware, you can ssh into the cards.
- close04 8y agoThere's a non-exhaustive list here: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00088.html https://www.intel.com/content/www/us/en/security-center/advi... Intel® Atom™ Processor C Series Intel® Atom™ Processor E Series Intel® Atom™ Processor A Series Intel® Atom™ Processor x3 Series Intel® Atom™ Processor Z Series This being said, this is the current status for my old Atom N270 (2008): https://imgur.com/a/pbeJ306 https://imgur.com/a/pbeJ306 Unless the tool is wrong, but I think it was generally marketed as a reliable source. In which case maybe someone can recommend a reliable one to test the vulnerability.
- zzzcpan 8y agoTools usually just check CPUID and system configuration and don't actually test vulnerabilities. And not necessarily interpreting everything correctly. You can do that without running anything, just checking your OS updates and whether your CPU is out-of-order one, i.e. with speculative execution. N270 isn't and therefore isn't vulnerable. If you want to truly test speculative vulnerabilities, compile this program: https://github.com/Eugnis/spectre-attack https://github.com/Eugnis/spectre-attack (EDIT: although this one probably won't work on N270, since it uses rdtscp, that it doesn't have, need to find version with just rdtsc)
- nine_k 8y agoRunning only trusted code on a server is much simpler than on a desktop / laptop: no Javascript in browser.
- PeCaN 8y agoLuckily, most old Atoms are really simple in-order processors that aren't vulnerable to Meltdown/Spectre.
- Filligree 8y agoAMD seems considerably more on top of the security game. As for ME, make sure you avoid any system on which it is enabled.
- monochromatic 8y agohttps://en.wikipedia.org/wiki/AMD_Platform_Security_Processor https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...
- ekianjo 8y agoThat's just because AMD is the underdog and it not as well studied as Intel. Given the same scrutiny I'd wage it would be as bad as Intel.