9 ms·
Everybody who studied even a little bit about processor hardware new about speculative execution. And it was never just intel that was using it, (they all were)
by TheSoftwareGuy 7y ago
Everybody who studied even a little bit about processor hardware new about speculative execution. And it was never just intel that was using it, (they all were). Until Spectre that technology was not considered controversial.
the crazy thing is that nobody saw this until recently.
- samth 7y ago"Until event X, doing <thing that X demonstrated was bad> was not considered controversial" is an explanation of behavior, but not really a defense.
- marcoperaza 7y agoNegligence, recklessness, knowledge, or purposefulness are probably the only way actions can be wrongful. To have acted negligently, you at least ought to have known that it carried an unacceptable risk. So you need a story on how it was at least negligent and why they ought to have known the risk before releasing the product.[0] Mere causation can’t get you there. E.g. when a car hits a pedestrian, the driver and pedestrian equally “caused” the accident. It is only by way of characterizing their behaviors in one of the ways above that we can identify wrongdoing. Perhaps the driver wasn’t paying attention (negligent or reckless) and ran a red light. Or perhaps the pedestrian was intentionally throwing themselves in front of traffic. Etc. [0] Products liability law on its surface does eschew the moral-wrongdoing requirement in favor of strict liability for some kinds of product defects. But that has to do with economic incentives, practical ability to prove claims, etc.
- rayiner 7y agoHere, chip makers never promised to prevent X. Maybe preventing X is desirable now that people do Y, but you can hardly blame them for not preventing something they didn’t promise to prevent.
- shawnz 7y agoThey promised to develop general purpose chips which can meet as many desktop computing needs as possible, which now implicitly includes need Y (but they didn't anticipate that at the time). They could of course just reject the necessity of need Y, but if the majority of their clients actually do have need Y, can it really be said that the chip is successful at being general purpose?
- rat9988 7y agoYeah you can. Because the chip provides capabilities so you can do such protections in software if you want, or get more speed if you don't want.
- orbital-decay 7y ago> the crazy thing is that nobody saw this until recently. Correct me if I'm wrong, but speculative execution attacks (or at least the possibility) were known for several years before Spectre.
- MiroF 7y agoYou're not wrong - side channel attacks have been around for forever
- gpderetta 7y agoNot all side channel attacks rely on speculation, although I think all known speculation attacks necessarily rely on side channels to exfiltrate information. I'm not an expert but I think that specifically attacking speculation was novel.
- mrfredward 7y agoFor anyone who hasn't come across it, here's a really interesting blog post about speculative execution and a cache bug in the Xbox360 (2018 post about stuff that happened in 2005): https://randomascii.wordpress.com/2018/01/07/finding-a-cpu-design-bug-in-the-xbox-360/ https://randomascii.wordpress.com/2018/01/07/finding-a-cpu-d...
- marcosdumay 7y agoYou say that like if Intel flaws were comparable to the ones from ARM and AMD. They aren't.
- kllrnohj 7y agoAnd this post isn't about those flaws, so that's irrelevant.
- gcb0 7y agothat's victim blaming. chip consumers missing a communication is very different from intel actively developing this to cut corners for raw performance (which is the only reason they cornered the market) and forcing all other manufacturers to follow up or die.
- jcranmer 7y agoSpeculative execution was developed by IBM in the 1960s, before Intel made CPUs.
- monocasa 7y agoTo be fair, untrusted code wasn't part of the security model for mainframes for the longest time.
- wglb 7y agoThis is one of the discoveries that you see then slap your forehead saying "Duh of course!"