3 ms·
AMD has fared better in the age of speculative execution attacks because they didn't allow their speculation to "cheat" and break hardware protection barriers,
by cookiecaper 7y ago
AMD has fared better in the age of speculative execution attacks because they didn't allow their speculation to "cheat" and break hardware protection barriers, even though several of their major competitors did.
While it's by no means a guarantee, it does say something about the engineering culture that they understood the theoretical risks of violating a protection barrier and chose to respect those boundaries, instead of dismissing the risk and going for the bigger stats. That deserves notice and approbation.
- makomk 7y agoYeah, it really does seem like a fundamental difference in how AMD and Intel designed their processors. Researchers have found Intel processors allowing speculation to bypass hardware protection all over the place, and they just haven't found an AMD equivalent. Not only that, AMD have looked into this themselves and released an entire whitepaper explaining why this isn't possible: https://www.amd.com/system/files/documents/security-whitepaper.pdf https://www.amd.com/system/files/documents/security-whitepap... (With, interestingly, one exception. Apparently AMD CPUs allow speculative execution to ignore x86 segmentation. It's just that no-one cares because that's not used anymore. I'm not sure there have even been any mainstream OSes that used that for process isolation.) This is particularly bad for Intel because most of the SMT-based exploits can pretty much only be mitigated by disabling SMT entirely and taking such a substantial performance hit that they've been trying desperately to convince people not to.
- wahern 7y ago> I'm not sure there have even been any mainstream OSes that used [x86 segmentation] for process isolation. AFAIU OpenBSD uses it for W^X (aka DEP) on i386. Linux may, too.