39 ms·
Make Linux Fast Again (2019)
- throwaway888abc 7y agoThere should be some disclosure that it will make it fast but very insecure
- taneliv 7y agoWell, if you have an idea what to do with the undocumented string returned by the site, maybe you also have an idea of what effects it might have, beyond making linux fast again?
- _nalply 7y agoIf someone suggests something I am not taking it seriously without good explanations.
- thaumasiotes 7y agoAs mentioned in another comment: https://linuxreviews.org/HOWTO_make_Linux_run_blazing_fast_(again)_on_Intel_CPUs https://linuxreviews.org/HOWTO_make_Linux_run_blazing_fast_(...
- ainar-g 7y agoImportant quotes: > You are (probably) an adult. You can and should wisely decide just how much risk you are willing to take. Do or don't try this at home. You do not want to try this at work. > As the above charts show: The effect of default parameters vs mitigations=off is measurable but not hugely impressive. (…)
- nullc 7y ago> You can and should wisely decide just how much risk you are willing to take That requires informed consent. But we can see that people are not well informed: many don't realize that a web broswer or an attacker accessible network stack are attack vectors. I've been using these options for a while (well, mitigations=off is new to me)... on dedicated rendering computers that are on a port isolated network inaccessible to the internet and without the ability to make outgoing connections at all. That's probably (I hope?) a reasonable usecase for these settings... but not exactly a super common one.
- Kwantuum 7y agothere is nospectre_v1 and nospectre_v2 written in there, unless you've been living under a rock you should get a pretty good idea that this is not a very safe thing to do.
- Hackbraten 7y agoIt depends on your threat model.
- castis 7y agoCould you go into detail on what you mean here?
- badsectoracula 7y agoAre you Jeff Bezos, Bill Gates, Tim Cook or other high profile billionaire or head of state target or work for such a target? If yes, do not do what the site says. If not, it doesn't affect you. Such security measures take into account possibility, but usually ignore probability.
- wyldfire 7y ago> If not, it doesn't affect you. I don't think I agree. Instead, I'd rephrase: "Do you ever use your web browser on this computer to go to less-than-trustworthy sites? Ones that use ad networks or load a cryptominer? Then you may not want to turn these on." The risk for most individuals isn't that they'll be held ransom, rather their property will be abused and they'll have to repair it.
- gjulianm 7y agoAre there any live exploits detected for Meltdown or Spectre? When talking about these vulnerabilities people seem to forget that these are pretty costly attacks: complex, slow (iirc at most you can read memory at 5kB/s) and require targeting to specific memory locations/software/etc. Why would an ad network or a cryptominer invest in such an attack when "Click here to download more RAM" still works?
- kfrzcode 7y agoIf one uses these flags without understanding exactly what they mean, then one deserves whatever painful experience they may encounter.
- papermachete 7y agoWhat pain, no exploits have ever been documented. These mitigations are makeshift insurance for datacentres.
- saagarjha 7y agoYou can download PoCs from GitHub right now.
- papermachete 7y agoI've yet to see reports of one running involuntarily in the wild.
- saagarjha 7y agoProbably because most systems quickly adopted mitigations and attackers then moved back to lower-hanging fruit.
- WanderPanda 7y agoSo you are saying the anti-vaxxers of the linux world are protected by herd immunity? Interesting angle for sure!
- pixl97 7y agoIn March of 2019 there were no world wide pandemics forcing hundreds of millions to shelter in place. The point is you vaccinate before a illness starts spreading if you can, because things spread quickly when you do not and can create quite a mess.
- 7y ago
- miles 7y agoThe GRUB parameters that appear on Make-Linux-Fast-Again.com apparently disable Spectre/Meltdown mitigations: https://gist.github.com/rizalp/ff74fd9ededb076e6102fc0b636bd52b https://gist.github.com/rizalp/ff74fd9ededb076e6102fc0b636bd... https://securitronlinux.com/bejiitaswrath/how-to-get-a-nice-speed-boost-for-ubuntu-this-really-does-work-well/ https://securitronlinux.com/bejiitaswrath/how-to-get-a-nice-... https://www.phoronix.com/scan.php?page=news_item&px=Spectre-Meltdown-Easy-Switch-52 https://www.phoronix.com/scan.php?page=news_item&px=Spectre-...
- jcelerier 7y agoYes, that's the point of this site - if your workflow is hurt by the perf impact of mitigations and SPECTRE & friends are not a credible attack, for instance because you disable JS by default, then you can just curl and pipe this to your kernel parameters
- miles 7y ago> Yes, that's the point of this site Sorry - was just providing a bit more information for those of us who didn't immediately grok the point of a site which is literally just: noibrs noibpb nopti nospectre_v2 nospectre_v1 l1tf=off nospec_store_bypass_disable no_stf_barrier mds=off tsx=on tsx_async_abort=off mitigations=off
- jcelerier 7y agohm, I'm not a native english speaker - was my tone incorrect ? was just trying to add more context
- deleted 7y ago[deleted]
- jshevek 7y agoI thought your tone was fine, but the phrase "Yes, that's the point..." can sometimes (not always) be associated with a condescending, sometimes even impatient, tone. It's not intrinsic to the phrase, it depends on what the reader may associate with the phrase. (I'm also not saying this actually happened in this case, I'm just speaking generally.)
- jankotek 7y agoOr use AMD....
- Arnavion 7y agoSpectre mitigations are applied for both Intel and AMD.
- jankotek 7y agoOnly partly > Based on external and internal analysis, AMD believes it is not vulnerable to the SWAPGS variant attacks because AMD products are designed not to speculate on the new GS value following a speculative SWAPGS. For the attack that is not a SWAPGS variant, the mitigation is to implement our existing recommendations for Spectre variant 1. https://www.amd.com/en/corporate/product-security https://www.amd.com/en/corporate/product-security
- saagarjha 7y agoMost of the Spectre variants do affect AMD as well, however.
- papermachete 7y agoAMD only just now released laptop CPUs that can compete with intel.
- dirtydroog 7y agoWhat has that got to do with anything?
- papermachete 7y agoThere was no incentive go to with AMD so now a ton of people want their Intel performance back instead of buying a new PC. Heck, this also applies to FX CPUs.
- 7y ago
- basementcat 7y agoWindows version is here: (scroll down to where it says "Manage mitigations for CVE-2017-5715") https://support.microsoft.com/en-us/help/4072698/windows-server-speculative-execution-side-channel-vulnerabilities https://support.microsoft.com/en-us/help/4072698/windows-ser...
- pojntfx 7y agoOh can NT just die already pls
- papermachete 7y agoHere, run as admin and click disable, restart. https://www.grc.com/inspectre.htm https://www.grc.com/inspectre.htm
- carlhjerpe 7y agoWould be nice if grc could release the source for this tool so people could see what it queries/sets to function.
- deleted 7y ago[deleted]
- badsectoracula 7y agoThe irony here is that these mitigations were meant to save from potential threats that most desktop users will never be suspect to, yet people who want to get back the performance of the computers they paid for are going to attempt doing that by running programs that they have no idea what they are actually doing which is a more likely way for getting their systems infected than anything these mitigations would protect. After all it is much easier to tell someone "here, click this as an admin to make your computer fast" and directly extract any data you want, than try and take advantage of all the issues the mitigations fix and the gamble that all the assumptions you are making will be correct.
- 7y ago
- dsign 7y agoAre there any javascript exploits, on desktop, of these?
- saagarjha 7y agoSpectre v2, possibly?
- jankotek 7y agoSerious question: In old Sandy Bridge days it was recommended to disable hyperthreading. That would decrease heat produced by CPU and allow better overclocking (2600k versus 2500k debate). Are there some features in CPU (such as hyperthreading), I can disable, so I can run system without those workarounds? I think faster Linux kernel could offset slightly lower CPU performance. Also there is lower energy consumption on laptop...
- petronio 7y agoOn Intel: For some mitigations disabling hyperthreading will disable them as some vulnerabilities are only present with it enabled. That being said, the overall performance impact will be greater from disabling hyperthreading than by enabling the mitigations (though some vulnerabilities remain so long as you don't disable hyperthreading). I wouldn't expect lower energy energy consumption from disabling hyperthreading: completing tasks faster allows the CPUs to reduce frequency faster.
- dgrant 7y agoHow much of a difference will these make? Trying to decide if it's worth my time.
- PureParadigm 7y agoI don't think there's an easy answer. It will very much depend on your hardware and what kind of software you run. I'd say the best way to tell is just to try it, measure performance, and compare results.
- Kwantuum 7y agoConsidering it takes all of 15 seconds to setup (5 minutes including reading), it's really not a matter of if it's worth your time, but if it's worth the risk, since it disables mitigations for hardware vulnerabilities.
- softwarejosh 7y agofirst, do you use js?
- dvfjsdhgfv 7y agoYou make it sound as if JS was the only attack surface, whereas it's just the most common one.
- saagarjha 7y agoI did not get that impression at all from that comment, FWIW.
- irthomasthomas 7y agoI did this on my i5 4300U laptop and whilst I didnt formally benchmark it, the boot time halved, and it feels a LOT faster to use. So much snappier.
- CodeArtisan 7y agoonly mitigations=off is enough now. more information at https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html https://www.kernel.org/doc/html/latest/admin-guide/kernel-pa... search for mitigations=
- jcelerier 7y agoI let it because there were kernels with the no...=off flags but not mitigations=off yet.
- sneak 7y agoTo clarify parent comment: if you understand the security risks and wish to turn off these mitigations, on modern kernels the entirety of the linked website's kernel args can be shortened to: mitigations=off All of the rest is now redundant. TIL: the default `mitigations` value, `auto`, leaves SMT enabled—even if it's vulnerable(!!!)—to avoid surprising sysadmins who upgrade to find SMT disabled. The full protection, non-default option is: mitigations=auto,nosmt Thanks for the doc link!
- joombaga 7y ago>> the default `mitigations` value, `auto`, leaves SMT enabled—even if it's vulnerable(!!!) Is SMT always vulnerable? Is there a way to only disable SMT if it's vulnerable on the target system?
- petronio 7y agoTo my knowledge it's always vulnerable on Intel processors, but not on AMD ones due to architectural differences. The nosmt option, when added to the mitigations option, should only disable SMT on vulnerable processors according to the Linux admin guide.
- naranja 7y agoI stumble over the "…make xx again". Repelling. But maybe the metaphor to oversimplification and ignorance of the deeper problems is appropriate…
- jshevek 7y agoThis reads like flamebait to me. I don't see that it adds anything to the discussion.
- smcl 7y agoWhile it might be straying slightly towards the off-topic, the second part is a very astute observation and an interesting connection that I did not personally make at first glance.
- drekembe 7y agoIt's a relevant comment. The author chose a title with heavy ties to politics. They shouldn't then be surprised when people bring that up in discussion. I personally also think it's not wise to choose a title that enforces a slogan with ties to hateful politics unless that was your goal from the start.
- jpxw 7y agoLearn to take a joke.
- jshevek 7y agoAll political slogans have ties to politics which someone finds hateful.
- thosakwe 7y agoThis is silly to say. Why deliberately miss the point? "Finding" some hateful is not the same as being on the receiving end of types of hate that have caused a lot of violence and persecution over centuries.
- superasn 7y agoDoing a little research I came across this article (1) which explains what the flags are for: (1) https://linuxreviews.org/HOWTO_make_Linux_run_blazing_fast_(again)_on_Intel_CPUs https://linuxreviews.org/HOWTO_make_Linux_run_blazing_fast_(...
- nkkollaw 7y agoLinux 2020! :-D
- dvfjsdhgfv 7y agoOr, you can use AMD.
- saagarjha 7y agoAMD has speculative side channels as well…
- tasubotadas 7y agoIf I disable these fixes, how likely (how much effort?) it is that somebody would make use of these vulnerabilities? AFAIK, I (my personal workstation) would only be exposed via browser JS so if I do not spend too much time on shady sites, I should be good?
- papermachete 7y agoYes, a lot of these mitigations have demoscene on github so you can run an exploit locally.
- saagarjha 7y agoThere are ready-made Spectre exploits that will attack your browser if it hasn’t been hardened yet; these kinds of exploits are fairly straightforward. Spectre v2 is harder to pull off, but can reach across processes and so you’re presumably vulnerable to that.
- kstenerud 7y agoBasically: If you're fine with every program running on the system (including web browser in your case) having full, unfettered access to everything else on the system, then it's fine to disable the fixes. In other words: Only do this on systems where you actually trust each running program not to be compromised in its day-to-day operations and turn against you. Anything that runs arbitrary code from an outside source (for example JS) is not safe.
- tasubotadas 7y agoI trust all of my programs as I use either only open-source or "big-player" packages. The only problem would seem to be JS from shady websites. I guess now the question is, how much time to I have to spend on that site before it can get my private ssh keys?
- spockz 7y agoThe JavaScript of shady adverts that sometimes pop through can also occur on no. Shady websites. So you are not entirely safe by only browsing safe sites.
- emadmokhtar 7y agoIs this needed for AMD based machines
- chronogram 7y agoYou can run the Phoronix test suite before and after enabling them. There's not a lot of data on the various recent AMD platforms, presumably because of the smaller market share especially until recently. I imagine there's a large difference between mitigations=on and mitigations=off on the pre-Zen AMD platforms and a smaller difference between the two on the most recent AMD generation.
- smabie 7y agoWhat kind of performance gains would an AMD Zen2 system receive from disabling all of these mitigations?
- smabie 7y agoIs there any public PoC that can exploit an Intel or AMD system with mitigations=off? And if so, what kind of access is needed?
- axegon_ 7y agoUnless you're doing it on a computer completely off any network and doesn't have any form of communication with the outside world, that's a very bad idea. Edit: Ok, plenty of people already said things in that context already apparently...
- tomcooks 7y agoI suggest adding a quick paragraph explanation, at first I thought that the server had been hugged to death Thanks for this
- ThePhysicist 7y agoDoes anyone know a benchmarking utility that can quantify the impact of these mitigations? I mean I don't do much CPU bound work like heavy compiling on my machine, but I would nevertheless be interested in seeing what the effect is.
- jlgaddis 7y agoThe phoronix.com site has ran several benchmarks with these mitigations on and off.
- boudin 7y agoI guess you can use phoronix test suite: https://www.phoronix-test-suite.com https://www.phoronix-test-suite.com Those migrations are benchmarked quite frequently on phoronix.com, for example: https://www.phoronix.com/scan.php?page=article&item=3900x-9900k-mitigations&num=1 https://www.phoronix.com/scan.php?page=article&item=3900x-99...
- dang 7y agoSmall previous threads: https://news.ycombinator.com/item?id=19928110 https://news.ycombinator.com/item?id=19928110 https://news.ycombinator.com/item?id=19936386 https://news.ycombinator.com/item?id=19936386
- m0xte 7y agoI thought this was going to be a replacement for all the free desktop crap for a minute. Now I’m disappointed.
- Legogris 7y agoWould be good with some context on motivation and impact. Some of these are specific to x86, for example.
- deleted 7y ago[deleted]
- irthomasthomas 7y agoI did this on my laptop a few months ago. It was like getting a new computer. I haven't benchmarked it, but boot time halved and it felt much faster to use.
- chris_wot 7y agoNeeds a domain http://make-linux-insecure-again.com http://make-linux-insecure-again.com
- grandinj 7y agoExcellent, thanks! I have a box where literally the only thing I care about is CPU speed (build cluster) and nothing on that box is worth anything at all.
- silly-silly 7y agoWhat about the thing you're building ?
- nevi-me 7y agoI'm saying this lightly, but in some cases malware starts with boxes where nothing in them are worth anything at all, where CPU speed and an Internet connection are tools for botnets.
- tsimionescu 7y agoFortunately, neither Spectre nor Meltdown allow write access of any kind.
- pixl97 7y agoAt least until it reads credentials out of memory.
- betimsl 7y agoBuild clusters almost always run in a local network without internet connection. Or with connections to specific hosts.
- jwr 7y agoI did my own testing a while back, because I wanted to measure if these actually make a performance impact for my use case. Net result: they do not. For my use case (Clojure/JVM and ClojureScript compilation), compile times did not get shorter. There seemed to be a slight improvement, but it was below the level of measuring noise (which was around 8%). My conclusion was that while the system might indeed be faster by several percent, it is not measurable in my case, so I should not even bother, given the possible risks.
- coldpie 7y agoNice work. Anyone claiming performance improvements without an accompanying benchmark that is relevant to your usecase is wasting your time.
- irthomasthomas 7y agoMy experience was different. My laptop boots in half the time with these mitigations disabled, and is noticeably much faster to use.
- asdfasgasdgasdg 7y agoThat's weird. I don't think anyone has measured these mitigations at a 50% perf hit even on crafted workloads. I wonder if something else is going on.
- lallysingh 7y ago15% of pure cpu, but that doesn't take the consequences of the CPU improvement in other systems (e.g. crypto fs leading to higher iop rates, etc).
- ogre_codes 7y agoRunning insecure performance enhancing kernel mods to speed up crypto fs.... It's a self defeating performance tip!
- sneak 7y agoIs there anything like this for macOS (for systems that do not run any untrusted code/scripts or are not internet connected, of course)?
- astrange 7y agoThere might be some under 'sysctl -a'.
- justaj 7y agomds=off Does this mitigate MDS attacks? https://mdsattacks.com/ https://mdsattacks.com/
- 40four 7y agoAmazing that a 'website' like this can make the top page. Just a plain un-styled string of, presumably, some sort of configuration. No explanation on how to use it, or what it does. I see 'specter' in there so there's a clue. I mean, after reading comments/ googling/ etc. I understand now, but at first I thought the site was broken. Wouldn't it have been better to post an actual write up that explains what this is? We are setting the bar really low here :)
- captain_price7 7y agoI guess the shocking simplicity is part of the appeal
- pluc 7y agoI see is as a sort of expertise threshold. It's not for you if you don't get it, but if you do there's lots to discuss. It's what relevance used to be without marketing.
- 40four 7y agoHaha, I suppose that is what they were going for. I'll admit it's not for me. I definitely don't go poking around in my GRUB config very often, but, after reading the write ups others have posted, I did learn some new things, so there's that. From other commenters: https://linuxreviews.org/HOWTO_make_Linux_run_blazing_fast_(again)_on_Intel_CPUs https://linuxreviews.org/HOWTO_make_Linux_run_blazing_fast_(... https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html https://www.kernel.org/doc/html/latest/admin-guide/kernel-pa...
- jcelerier 7y agoI'm the author - the idea was, that you would be able to do curl -s https://make-linux-fast-again.com | awk '{ print "GRUB_CMDLINE_LINUX_DEFAULT=\"" $0 "\"" }' >> grub.cfg to use the parameters directly (it's a joke ! don't !), which would not be possible if there was any other content on the webpage (at least without taking more than the 2 minutes this joke took to set up)
- Pedrit0 7y agoPromoting to disable the spectre mitigation should at least come with explanation and warning...
- jsjddbbwj 7y agoYou're supposed to investigate those before you use them.
- carlisle_ 7y agoThat’s why there’s no warning labels or disclaimers anywhere else in life right?
- Pedrit0 7y agoMore broadly I am just wondering if this submitted link to 'Make Linux Fast Again' is just relevant. Let me explain: - For tech savvy people, the boot options disabling the spectre mitigation are a very poor information as it takes 2 secs to find it with google. A 'rich' information would also consider the expected gains in terms or performance and the risks in terms of security, which might be the only matters for people who wonder if they should do it, assuming that making the change by itself is an easy and fast operation. - For non tech savvy people, the boot options mean nothing at all, so they will not be able to benefit about the information as nothing is explained. So if this submitted link is useless for both tech-savvy and non tech-savvy people, who is it intended to ? If it is intended and useful to no one, is it relevant ?
- ipunchghosts 7y agonoibrs noibpb nopti nospectre_v2 nospectre_v1 l1tf=off nospec_store_bypass_disable no_stf_barrier mds=off tsx=on tsx_async_abort=off mitigations=off
- pluc 7y agobecause you can doesn't mean you should
- sacman08 7y ago1. Get rid of systemd 2. Done
- foobarian 7y agoThe thing I would really like to figure out is how to prevent a Linux system from essentially livelocking when it close to runs out of memory. We've all seen it. Try to ssh in, connections get established but do not proceed. If you're lucky to have a console shell open from before, it shows gigantic load. Wish there was a way to put a few system critical processes into a container to guarantee them some resources.
- nialv7 7y agoI've heard that is problem is caused by Linux's overcommitting strategy. Basically, initial memory allocation never fails (unless you set special flags), but no memory is actually allocated on the spot. Memory is only allocated when it is accessed. And if Linux runs out of memory when a program accessed a piece of yet to be allocated memory, it will try really _really_ hard to free up memory so that memory access can success. That's what's causing the lock ups. Sounds to me this would be difficult to fix without breaking backward compatibility. In the mean time, you can probably improve your quality of life quite a bit by using something like: https://github.com/facebookincubator/oomd https://github.com/facebookincubator/oomd
- lallysingh 7y ago.. or swap?
- bluedays 7y agoor both!?
- diegocg 7y agoIt's more complex than that. Doing lazy allocation is not the problem, it's a common optimization. The problem comes when Linux does allow programs to (lazily) allocate a total amount of memory than is larger than the available RAM+SWAP before failing allocations. Then, when processes actually try to use that RAM, there is no physical place where to place that memory, and the only solution is to kill a process (OOM). This may certainly seem stupid at first sight. I don't remember the exact reason why Linux does this, but I remember that it was said that not doing it would imply not using all available RAM efficiently and allocations would start failing before expected or something like that. It's actually pretty easy to change this behaviour, there is a sysctl (/proc/sys/vm/overcommit_memory) that defaults to 0, but you can disable the overcommitting behaviour and even tune it. "2" does disable the entire overcommitting logic and it's what some people use to avoid memory trashing situations (but you still can get OOM in some situations IIRC) https://www.kernel.org/doc/html/latest/vm/overcommit-accounting.html https://www.kernel.org/doc/html/latest/vm/overcommit-account...
- nialv7 7y agoa.k.a Make Linux Unsafe Again.
- aruggirello 7y agoThat's insane. If you actually care about Linux performance so much, instead of poking security holes in your system, you might consider switching to Intel's Clear Linux (on AMD too) or (better yet) a performance-tuned kernel like XanMod: https://www.phoronix.com/vr.php?view=28805 https://www.phoronix.com/vr.php?view=28805
- sample2448 7y agoHow is it insane? Dropping few lines in grub cfg is much easier than installing a whole new kernel
- jbjohns 7y agoAnd dropping those lines of config is opening vulnerabilities on your system. In 2020, that's insane.
- RIMR 7y agoThis has some serious "I disabled my password to make logging in easier, but I'm still safe because the hacker would have to guess my username" vibes to it.
- sgt 7y agoFor what it's worth, I tried this on my home server and load average remains at 0.00 0.00 0.00 when the machine is doing nothing. That is perhaps understandable, but before I enabled mitigations=off, it was always at some kind of a load, e.g. 0.07 or so.
- superkuh 7y agoThe problem with this is that linux is no longer the OS. The browser is. And "modern" "browsers" do one thing, they automatically run arbitrary code from random places in a virtual machine. The very thing all these mitigations protect.
- testrun 7y agoYeah right, databases, app servers, network systems etc all run in a browser.
- 29athrowaway 7y agoThis is the same mindset that led the MAGA people to shut down the pandemics response team.
- dang 7y agoPlease don't post political flamebait to HN. It leads nowhere good. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- craftoman 7y agoMake Linux Vulnerable Again.