6 ms·
Have these tests been run with or without the security patches? Since Spectre/Meltdown/etc. it has increasingly been difficult to compare numbers. Lately intels
by std_throwaway 7y ago
Have these tests been run with or without the security patches? Since Spectre/Meltdown/etc. it has increasingly been difficult to compare numbers. Lately intels IPC advantage compared to AMD has been melted away completely by these patches. It will probably take some time until we can judge if these new IPC gains are solid or if they have been bought with new compromises.
EDIT: To clarify: If you compare both "out of the box" then the old one would be unsafe while the new one hopefully is safe because it comes with hardware/firmware patches built in. If you compare both patched, the old architecture gets a large performance hit compared to when it was launched. With time the patches usually evolve and change the performance characteristic. So you have to be careful which OS or firmware revision you are using. However way you do it, it's not an easy apples-to-apples comparison anymore unless you're talking about a very specific use case at a very specific point in time.
- w0utert 7y agoHow many of these security leaks still need software patches for Sunny Cove? I thought Intel implemented hardware mitigations for pretty much all of them in the 10th generation chips?
- nik736 7y agoI read somewhere that it would take several years and generations for them to be fixed on the hardware side.
- std_throwaway 7y agoSome "hardware patches" are microcode changes that also result in performance degradation.
- w0utert 7y agoMaybe, but that's hardly relevant when comparing performance of these chips to e.g. Ryzen 2, as there is no way to disable these mitigations on Ice Lake anyway, it's simply what you get out of the box.
- makomk 7y agoThe big gotcha is that meaningful mitigation of ZombieLoad on affected chips requires disabling Hyperthreading (the hyperthreading-based version of the attack cannot be fixed in microcode or software) but Intel has taken the position that this isn't actually necessary on normal consumer machines. So when Intel say that they have hardware fixes for all this stuff it's not clear whether they mean they've actually fixed it.
- vbezhenar 7y agoSome security issues require software patches but those CPUs also include hardware improvements which strive to reduce overhead to negligible value. According to Anandtech [0] only Spectre V1 requires pure software mitigation. [0] https://www.anandtech.com/show/14664/testing-intel-ice-lake-10nm/3 https://www.anandtech.com/show/14664/testing-intel-ice-lake-...
- std_throwaway 7y agoThis sounds very promising. But it also sounds like something that PR would write. I think we'll have to wait some time until independent researchers get their hands on these chips and give them a thorough testing.
- close04 7y agoI'm also taking that with a grain of salt since AT has a habit of not challenging Intel that often, and only issuing some weak response even when it turns out it was PR. Of course this may not be the case this time.
- userbinator 7y agoI see the whole Spectre/Meltdown/etc fiasco as an interesting tradeoff: you can have higher performance if you don't care about those side-channel attacks, which is what a lot of applications like HPC are going to do anyway because they don't run untrusted code. That still gives Intel an advantage.
- AsyncAwait 7y agoIf they need to be explicitly disabled, which they do, not many are going to do it, not much of an advantage if you ask me.
- ajross 7y agoBig datacenters have large and talented engineering staff and routinely customize their machines and firmware heavily. Consumers aren't going to do it, that's true (and relevant to the article: all the Ice Lake parts mentioned are consumer chips). But on a per-revenue basis, most of the market is amenable to this kind of thing.
- radicalbyte 7y agoGamers are absolutely going to tweak every setting to increase performance of their machines.
- zrm 7y agoThe trouble is gamers are susceptible to it. They're running running all kinds of untrusted code (javascript, custom game levels created by other users) as well as receiving untrusted game data from other users in multiplayer games which commonly then goes through a data parser optimized for performance over security.
- brianwawok 7y agoWhile perhaps true in theory, has there ever been a known case where game DATA from a multiplayer game was able to exploit a remote system and say obtain root access? Stuff like rowhammer is very different vs something like a SQL injection on a website.