4 ms·
There's an opportunity for someone to sell "reasonably" secure hardware at this price point. Especially since Intel certainly isn't selling anything that fits t
by willtim 7y ago
There's an opportunity for someone to sell "reasonably" secure hardware at this price point. Especially since Intel certainly isn't selling anything that fits this description.
- coder543 7y agoI think AMD already has that covered with Epyc 2 (Rome) processors. POWER is also known for being highly SMT, which could lead to them being even more prone to the issues that plagued Intel's implementation of hyperthreading. A single POWER9 core has 4 to 8 threads.
- dralley 7y agoI would expect that it would actually be much harder to pull off such an attack, because you've got 4 threads fighting over the same resources instead of 2. These attacks essentially require statistical analysis, and the more noise there is the more difficult the attack would be. If you've got more than just the attacker and the victim threads running on a core than it's a noisier environment to pull off such an attack.
- coder543 7y agoThat’s a good point. Also imagine if the attacker controlled 7 out of the 8 threads on a core... maybe they would have even clearer statistics for analysis. Or maybe POWER9 is completely secure. My main point was that Epyc has already proven to be much more resistant to these attacks than Intel’s architecture, and it wouldn’t require dealing with porting your applications to run on a niche ISA, with very limited options to buy server hardware, and very few (if any) options to rent cloud instances on POWER9.
- rst 7y agoPeople who are troubled by security issues in Intel's Management Engine may also be suspicious of the firmware in AMD's roughly equivalent Platform Security Processor, which doesn't have a spotless record either. See, e.g., https://www.theregister.co.uk/2018/01/06/amd_cpu_psp_flaw/ https://www.theregister.co.uk/2018/01/06/amd_cpu_psp_flaw/
- coder543 7y agoI think we were talking about Spectre, Meltdown, and related attacks. Not the PSP or IME, although those are concerning too.
- floatboth 7y agoWell, Spectre affected pretty much all processors except very slow ones (Cortex-A53) :)
- coder543 7y agoIt affected AMD's Zen architecture significantly less. A number of exploits that applied to Intel didn't apply at all to Zen, and the ones that did apply had less costly mitigations than Intel.
- bogomipz 7y ago>"POWER is also known for being highly SMT, which could lead to them being even more prone to the issues that plagued Intel's implementation of hyperthreading." Which SMT issues are you referring to here on Intels?