4 ms·
Ok, but "Intel fail" indicates meltdown was specific to Intel processors, when it was also present of IBM and some Arm designs.
by rrss 6y ago
Ok, but "Intel fail" indicates meltdown was specific to Intel processors, when it was also present of IBM and some Arm designs.
- p_l 6y agoI specifically separated the "new class of microarchitecture timing attacks", which was common across many systems (including AMD, POWER and ARM), from "Intel fail" where too aggressive optimization tricks did turn out to be bad idea.
- jeffbee 6y ago"Too aggressive" is just, like, your opinion, man. There are tons of workloads where only maximum throughput or lowest latency are important and the operators of those systems don't care one jot about side channel attacks.
- wizzwizz4 6y agoAnd PC / general-purpose CPUs aren't such a workload.
- cthalupa 6y agoThey aren't? I know a significant number of people who have disabled spectre and meltdown protections in favor of higher performance because they are not concerned at all about side channel attacks. Single tenant workloads that run no untrusted code that are not public facing are not exactly a unicorn.
- deleted 6y ago[deleted]
- tedunangst 6y agoWhat specific optimization are referring to? The one you mentioned, moving access auth checks to retirement, was something both ARM and POWER did.
- p_l 6y agoNeither ARM nor POWER did that - they had timing side channel from speculative execution (i.e. whether a branch was taken or not). What Intel did was put all memory access auth checks to retirement, so appropriately crafted code could bypass protection bits in TLB, not just snoop elements of cache (AMD, ARM, POWER)
- rrss 6y agoYes, they did. Intel's implementation of checking permissions in parallel with speculative loads was vulnerable because the transient effects could be observed through cache timing information. All of these attacks, meltdown included, use "timing side channels from speculative execution." POWER9 had the same problem (and therefore was similarly vulnerable to meltdown) for memory accesses that hit in the L1. i.e. userspace accesses to kernel addresses cached in the L1 could produce observable data-dependent effects because the data was available for further speculative execution before the permission exception was raised. This is why the Linux kernel put in place a mitigation for meltdown on POWER CPUs that involves flushing the L1-D cache on transitions to/from kernel space ("RFI flush"). To be clear, the vulnerability that Intel processors have because they "move memory access verification to instruction retirement" is called "meltdown." When I said that meltdown was present on IBM and some Arm designs, I meant that these designs are vulnerable to the same exploit because they have comparable problems with regard to memory permission checks. I was not referring to the various other spectre-type vulnerabilities, which are even more widespread. So to summarize: Ok, but "Intel fail" indicates meltdown was specific to Intel processors, when it was also present of IBM and some Arm designs.