3 ms·
Except HPC clusters do need all the Spectre/Meltdown fixes and more. Those are shared environments (with the exception of a handful of people who got research g
by tagrun 7y ago
Except HPC clusters do need all the Spectre/Meltdown fixes and more. Those are shared environments (with the exception of a handful of people who got research grants for their own internal clusters). In fact, hyper-threading has also been disabled completely is some clusters.
- sliken 7y agoI'm sure there are some, I'd be very surprised it it was most though. The main problem with Spectre/Meltdown and friends is two VPSs under the same hypervisor sharing a core running some webstack. With careful analysis of tlb, cache timings, and related you can extract SSL private keys, bitcoin addresses, and similar information that would normally be quite hidden since you are running in a different kernels sharing the same hardware. With a HPC cluster you are (generally) running on bare metal (no hypervisor), single linux kernel, and can see what the other user (if there is one) with simple tools like ps, w, top, and friends. Additionally there's generally not private keys for SSL or bitcoin addresses. In fact often unencrypted network filesystems are used sending plain text over the wire. Even on more sensitive clusters the security is highest between the internet and the head node and less so between compute nodes. Hyperthreading being on vs off is usually just an issue with the performance characteristics of whatever application is most common and the limitations of certain batch queues like sun grid engine (SGE). If your popular app hates hyperthreading then you turn it off. Or sometimes you want to minimize the performance impact of users sharing a core. Additionally sometimes cores, or even nodes are not shared. But again it's for performance reasons not security. Last thing you want is a 10,000 core job to run 50% as fast because one node is shared with a resource intensive application.