9 ms·
ITX Motherboard with an Elbrus CPU
- dsr_ 6y agoReally interesting, until you discover: 1. No price. 2. Bootloader is proprietary. 3. (less concerning) No performance data. It's really hard to buy this as a security-focused open-source system without an open bootloader.
- jamesmd 6y agoI agree, the bootloader is a massive shame! Personally I’d rather go with a power9 based board. But let’s see where this goes, it’s certainly interesting.
- segfaultbuserr 6y ago> I agree, the bootloader is a massive shame! It reminds me of my Loongson 2F laptop powered by a Chinese MIPS processor, same model previously used by Richard Stallman. For a while (before Thinkpad X200), it was the go-to choice if one wanted a laptop with 100% free boot firmware and zero binary blob (the original boot firmware codebase is buggy and ancient, but with source, later GNU developers made it run GRUB 2). I got it just because it was an interesting non-x86 machine. It's a bit disappointing that a would-be Russian equivalent couldn't do the same (an understandable problem, the designers of the board have no control over it), otherwise it'll also be a more hackable and interesting platform, at least for those who are fans of exotic non-x86 systems and don't care about price or performance.
- djsumdog 6y agoSo it likely doesn't use BIOS or UEFI. I wonder if we're going to see the ARM situation where every distro will need a custom image just for this board/architecture. I wonder if we'll see support in mainline for this arch/platform.
- djsumdog 6y agoSo, is the Elbrus-8CB a SPARC architecture? Will mainline Linux for SPARC work with its proprietary bootloader, or will it need custom patches?
- tyingq 6y agoMore info: https://www.anandtech.com/show/15823/russias-elbrus-8cb-microarchitecture-8core-vliw-on-tsmc-28nm https://www.anandtech.com/show/15823/russias-elbrus-8cb-micr... https://www.yumpu.com/en/document/read/54543367/the-elbrus-architecture-series-for-servers-and-supercomputers https://www.yumpu.com/en/document/read/54543367/the-elbrus-a... So, a SPARC like CPU, but the use case appears to be running either native Elbrus OS (Linux) or x86-64 through some sort of optimized emulation. "Direct execution of 20+ Operating Systems, including: MSDOS, Windows XP, 7, Linux, QNX, PS/2." This seems to indicate the emulation is somewhat like what Apple is doing with the M1: https://images.anandtech.com/doci/15823/VVolkonsky-RSCDays-2015-page-005_575px.jpg https://images.anandtech.com/doci/15823/VVolkonsky-RSCDays-2...
- ddol 6y ago> MCST’s proprietary C/C++ compiler and bootloader will be provided only as binary, because we do not have access to the source code of this part. Buy a “security focused” computer where the compiler is not open source, and the CPU/ICs have not been decapped, imaged and analysed from a manufacturer with ties to the Russian government? No thank you. I would not be surprised if there is a hardware Trojan in this machine.
- tyingq 6y agoI'd put it in the same category as using Yandex as your email provider. That is, probably somewhat safer from "5 eyes", but open to Russia. There's probably people for who that's a valid, useful setup.
- richardwhiuk 6y agoPeople who work for the Russian government?
- tyingq 6y agoPeople doing things that they don't want the FBI/IRS/etc to see, but don't care if Russia sees is probably a broader set than that.
- ardy42 6y ago> People doing things that they don't want the FBI/IRS/etc to see, but don't care if Russia sees is probably a broader set than that. If you want to avoid eavesdropping, it's probably best to avoid email altogether and use something designed for that purpose (like Signal). I don't see how you would get the effect you describe by using Yandex unless you did something like only ever emailing other Yandex accounts.
- hollerith 6y agoJust because someone used Yandex as a hyperbolic analogy doesn't mean we're talking about Yandex.
- thraneh 6y agoNothing deep, but the PCB layout is quite impressive. This project appears to care about the details. Also intersting to learn about the history of Elbrus.
- baybal2 6y agoIt's dotted with patently prehistoric ICs, AND it also employs a standalone "bridge" chip at the same time. There is not a chance that they hope to make money on it.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- virogenesis 6y agoBut can it run Doom?
- ohyes 6y agomost likely, you could run doom on a 386 in the 90s (this seems to surpass that).
- SV_BubbleTime 6y agoThat’s an interesting thought. With all the work to “run doom” there has been since the early 90s, I wonder how much of that effort would make Doom run better on that old hardware; I suspect not a lot. It ram poorly on 386 machines, and wasn’t until the 486-66 that it was acceptable and the first Pentium (P6?) that I remember it being smooth.
- trm42 6y agoIt ran smooth enough on 486/33DX with 10 Mb of ram. Actually it ran better on that than on 66 DX2 with 4 megs of ram.
- ohyes 6y agoThat would be interesting, I'd guess the floating point(and being twice as fast) were what really made a big difference. It is also interesting to think that smart refrigerators and automobiles end up with significantly more capable processors and hardware than early desktops. 'Running Doom' turns into more a challenge of getting an operating system and a working C compiler onto the device than one of optimization. I've often toyed with the thought of pushing the limits of the classic 2.5D FPS on modern hardware (without acceleration), pretty impractical being that most things have a GPU of some sort built-in at this point, but it would be interesting at least. When GPUs became available it seems like everything kind of moved towards more 'true' 3D where everything became defined geometrically (QUAKE etc) rather than via sprites.
- tadfisher 6y ago
- kingosticks 6y agoWhy is "temperature sensor trigger" listed under the 'security' bullet? If that's not a mistake, could someone please explain how that's a security feature?
- jeroenhd 6y agoI can't be 100% sure, but temperature fluctuations can often be used to execute side channel attacks on processors and chips on board. If the system analyses the temperature sensor for that, it might prevent leaking key material. I don't think I've seen anyone do that in practice though, it might just have been that they had to put _something_ extra in the security features and just added whatever sensor wasn't listed yet.
- kingosticks 6y agoThat would be my guess but that sounds really difficult to get right and you'd imagine all finds of false positives from it. The kind of feature you put in but leave disabled by default.
- extropy 6y agoDefense against cold boot attacks? https://en.wikipedia.org/wiki/Cold_boot_attack https://en.wikipedia.org/wiki/Cold_boot_attack
- numpad0 6y agoProbably a part of tamper detection. Not said anywhere but the spec looks like this is a good fit for military or industrial control panels.
- segfaultbuserr 6y agoIn embedded devices, the on-die temperature sensor can theoretically be used as a countermeasure to (the equally theoretical) high temperature fault injection attacks - the attackers heat up the chip until it starts flipping bits, then some security checks can be bypassed (e.g. see [0]). It's often proposed by the literature that the firmware should read the on-die temperature sensor constantly, and when it's outside the nominal operating range, halt execution, and possibly erase secret. However, while it's often proposed as such, I don't think it's actually useful - thermal fault injection is a real threat, but I said "theoretical" since it's the least of your problems when the attacker has physical access - both clock and power fault injection are easier. Nevertheless, at least a countermeasure to thermal faults is reasonable if you are just protecting a smartcard where everything is on a single chip. On the other hand, for a computer motherboard, such a sensor looks pretty useless. The target is simply too large to be protected (unless you can seal the entire system in a box fitted with sensors like a hardware security module). But I guess it is still a theoretical security feature, thus it was listed as such despite its uselessness. [0] https://eprint.iacr.org/2014/190.pdf https://eprint.iacr.org/2014/190.pdf > [...] We further presentheating faults by operating the devices beyond their specified temperature ratings. The efficiency of this kind of attack is shown by a practical attack on an RSA implementation. Finally, we introduce data remanence attacks on AVR microcontrollers that exploit the Negative Bias Temperature Instability (NBTI) property of internal SRAM cells. We show howto recover parts of the internal memory and present first results on an ATmega162. The work encourages the awareness of temperature-based attacks that are known for years now but not well described in literature. It also serves as a starting point for further research investigations.
- numpad0 6y ago> Cache: 1x PATA 8 GB (required as cache device for hardware emulation of x86 on Elbrus) wha-
- buildbot 6y agoYeah, I’d love more explanation of this. That seems way too slow and large to hold some kind of jit cache between x86 and whatever the core actually uses internally? Edit, there’s more info on other sites, it does look like the compiler cache? https://images.anandtech.com/doci/15823/VVolkonsky-RSCDays-2015-page-005_575px.jpg https://images.anandtech.com/doci/15823/VVolkonsky-RSCDays-2...
- miahi 6y agoIt might have a Compact Flash adapter on the back (CF cards are IDE compatible and with better response times than HDDs; they are still in use in some embedded systems, you just have to use a compatible filesystem, as they don't usually have internal wear leveling). Unfortunately I cannot find any pictures of the back of the motherboard, but if you look carefully at the pictures it seems that the board has two PCBs.
- MisterTea 6y agoCompact flash cards do in fact employ wear leveling. Though there may be some very old cards which do not. I have a few systems running 9front from CF. I also use CF cards in IDE adapters to replace spinning rust disks in retro systems. (edit: typo)
- NovemberWhiskey 6y agoMy thinking: this is basically in the category of national-prestige project, where the ability to do domestic production in certain product categories is basically about national self-image rather than a commercial concern.
- ardy42 6y ago> My thinking: this is basically in the category of national-prestige project, where the ability to do domestic production in certain product categories is basically about national self-image rather than a commercial concern. No, it's clearly a Russian national security project around supply chain security. IIRC, while the US is pretty good on the processor front, they have similar concerns around other ICs and components.
- f6v 6y agoIt's not like you can build a drone control station using Intel CPU if you're Russia.
- extropy 6y agoElbrus is very much security first chip/OS for Russia. With primary goal to avoid any western IP. The performance is probably ~5 years behind industry standard and price is probably 5-20x more. But that's fine, when the only buyer is government agencies and military contractors.
- SomeoneFromCA 6y agoEmulated x86 performance is somewhere around 1000 passmark units, roughly like Core Duo Pentium. Native number crunching is very impressive. Price is high to enable embezzlement of money by the top people in the Russian government.
- segfaultbuserr 6y ago> Native number crunching is very impressive. So unlike Transmeta, you can actually disable the x86 emulation and run native VLIW code on an Elbrus CPU? It's interesting. But I guess it's still not useful to independent developers in the FOSS community, it appears that MCST’s proprietary C/C++ compiler is the only compiler that can target the CPU.
- iagovar 6y ago5 years behind for a system you can actually use is pretty decent IMO. For a massive capital intensive business, high-tech, and with a much smaller internal market than China, that's quite an achievement.
- ardy42 6y ago> 5 years behind for a system you can actually use is pretty decent IMO. And probably more than adequate for the kinds of applications you'd use this in. Military technology needs to be state-of-the-art for ruggedness and reliability, not performance. For a similar example, look at the CPUs used in space missions: based on performance specs alone, the best ones would have been state-of-the-art in the 90s.
- 6y ago
- moyix 6y agoLast time this came up I wrote a bit about the history of Elbrus and why I think it's an interesting platform: https://old.reddit.com/r/hardware/comments/jx60fs/vliw_cpu_in_a_desktop_enthusiasts_crowdfund/gcyq0y2/ https://old.reddit.com/r/hardware/comments/jx60fs/vliw_cpu_i... I very much hope to be able to buy one at some point.
- 1MachineElf 6y agoNo mention about TDP. I wonder what it is. The ECC RAM could make this a good candidate for ZFS. I've subscribed to the CrowdSupply campaign: https://www.crowdsupply.com/sra-centr8/icepeakitx-elbrus-8cb https://www.crowdsupply.com/sra-centr8/icepeakitx-elbrus-8cb
- Pasorrijer 6y agoWhile I'd never buy this, I find it fascinating that outside of the Western lens there are still a ton of different and competing technologies. Reminds me of how Russia advanced research into Ternary computing considerably further than the West.
- villgax 6y agoA CPU-socket along the lines of AM4/LGA could be a good competitor for PCs with ARM chips, how they'd work with PCI-E GPUs is yet to be ascertained.
- richardfey 6y ago> I tried to buy an Elbrus-4C computer and have it shipped from Russia to the UK back in 2015 and it proved impossible. I find this to be the most interesting fact of the blog post...I wish author could elaborate more.
- jamesmd 6y agoBack then these were designed specifically for government agencies within Russia. Suppliers weren’t allowed to ship them outside of Russia unless you could prove it was for certain research projects. I found someone that was willing to buy a Elbrus motherboard and ship it to me, it got stuck at Russian customs and returned to the sender - fortunately he managed to return it to the supplier and I got my money back.
- trhway 6y agogiven the interest to the platform, it seems somebody in Russia can run a niche business - an Elbrus CPU cloud service, i.e. a garage with a bunch of Elbrus-es (though it is pretty pricey - the 1-4 socket systems with Elbrus 8S cost $5-$20K) Btw, couple months ago MCST established an official public forum for Elbrus users/partners/etc. Mostly in Russian, though most people there would understand English too. That is performance numbers - various Elbrus-es vs. i7 2600 - posted by a user there http://forum.elbrus.ru/viewtopic.php?f=38&t=6193 http://forum.elbrus.ru/viewtopic.php?f=38&t=6193
- djsumdog 6y agoSeems like the Russian equivalent of ITAR.
- joshu 6y ago“SPARK”?
- joshu 6y agoHeh, they edited it.
- oofabz 6y agoI don't see an ATX header on the motherboard. I wonder if this will be compatible with a standard PC power supply.
- pmiller2 6y agoDoes anybody else know what the nature of the "tampering sensor" and why there are exactly 2 of them? I'm guessing the reason for multiples is redundancy, but, then, why not 3 or more? Also, amusingly, I read "Fall detection sensor" as "Fail detection sensor" at first, and was really confused as to what that was. :P
- b0rsuk 6y agoI'm reading this at 00:53. I'm wondering why would a motherboard need an Autumn detection sensor...
- guenthert 6y agoVLWI, doesn't that imply no branch prediction (like Itanium, which afaiu expects the compiler to order instructions optimally ahead of time)? If so, shouldn't it be immune to SPECTRE?