4 ms·
While we're being honest, how many programs that get written are so desperate for performance that the only thing left to do is turn off security? And are the
by jbjohns 6y ago
While we're being honest, how many programs that get written are so desperate for performance that the only thing left to do is turn off security? And are the people who are able to even make this determination the kind of people for whom making a kernel module is unrealistic?
- skrebbel 6y agoYour comment would make sense if GP had written "but writing kernel mode code is very hard and only really smart people can do it". But they wrote something completely different. It seems to me like you just totally ignored their comment. What's the point of that?
- jbjohns 6y agoI didn't ignore it. My point is, the kind of people who truly need this kind of performance are already translating hotspots to assembler and so on, a kernel module is plenty practical for them. For nearly all computer users there is no excuse for turning off these mitigations.
- skrebbel 6y agoI don't know. If I'm running an application server with only my own code on a dedicated server, and I can flip some switches to make it go faster, then that's pretty nice, no? Might save me from upgrading to a bigger (pricier) server. What am I missing? I mean, sure, that site is nuts, it sorely needs documentation. But not every scenario needs Spectre protection.
- jbjohns 6y agoThe problem with the scenario you describe is: how will you ensure that no one ever forgets that this server is vulnerable and can never be used for certain things? And everyone on here advocating turning off the mitigations is assuming the only exploits are the ones we know about. But when has that ever been the case. If more people turn off the mitigations black hats will be invested in finding ways to exploit it we haven't realised before.