3 ms·
At this rate, with all these vulnerabilities and mitigations, we'll rollback CPU performance back at least 10 years.
by ancris 3y ago
At this rate, with all these vulnerabilities and mitigations, we'll rollback CPU performance back at least 10 years.
- javajosh 3y agoYep it's almost like Moore's Law in reverse.
- IlliOnato 3y agoThe only 100% reliable way is to turn off branch prediction completely, and yes, this would make the processors at least 2 times slower, perhaps more. Too bad that apparently nothing came out of the Mill architecture. My limited understanding is that this architecture would not have such vulnerabilities. Of course it's possible it would have others :-) but being much simpler, at least conceptually, perhaps it would have less and easier to mitigate. Oh well.
- Panzer04 3y agoGiven the classic stack overflow branch predictor question, you are underselling things quite a lot - a factor of 6 on those older processors in question, and who knows on modern processors. https://stackoverflow.com/questions/11227809/why-is-processing-a-sorted-array-faster-than-processing-an-unsorted-array https://stackoverflow.com/questions/11227809/why-is-processi...
- dzaima 3y agoI'd give at least a single order of magnitude for most code; maybe closer to two even.
- bob1029 3y agoIt seems to me like most don't have a fundamental gut feel for what speculative execution actually is and the implications of "not getting it". At some level we need to fight for performance. My operating systems are only getting slower and shittier. I cannot fathom my CPUs going backwards too. Security must take a back seat at some point. You can't put bubble wrap and warning labels over everything or it becomes useless. The most dangerous tools are typically the most effective. The CPUs are vulnerable because of the exact way in which they are being applied to a problem. Speculative execution is not inherently unsafe. Whatever future predicted memory prefetching shenanigans are going on in my CPU over here have absolutely ZERO impact on your CPU over there. Certainly someone could figure out a protocol/system/architecture that capitalizes on this notion that "2 different CPUs are indeed different CPUs". One can see how any perspective here still causes trouble for Amazon, Microsoft, et. al., but that was a business risk they signed up for the moment they intended to squeeze every last drop of subscriber revenue out of the hardware. Why should everyone else on earth have to suffer crappier performance by default because of the business/software practices of a select few?
- semiquaver 3y ago> Why should everyone else on earth have to suffer crappier performance by default because of the business/software practices of a select few? The author states in the article that they believe this may be exploitable from javascript in a browser. Just to hammer the point home, any web page could steal anything in memory on your computer. Spectre was also browser-exploitable, and was mitigated there partly by making access to high precision timers privileged. This is very much not a problem that only impacts cloud providers.
- CanaryLayout 3y agoThis is terrifying. You could hijack a user that has SAPGUI open, then push code updates to SE38 that spread everywhere.
- parasubvert 3y agoThese vulnerabilities have a lot less to do with cloud providers, and a lot to do with networked computers in general. It's not unreasonable to expect this exploit to be done via web browser, as was demonstrated with prior speculative execution exploits. Fundamentally, the only reason we need speculative execution is that we haven't updated our software to be more concurrent (reflecting how chips have kept pace with Moore's law for 15+ years), we still program as if we're in the 1970s. This may turn into a great opportunity to force a rebuild a lot of ancient code. For more information: C is not a Low Level Language https://queue.acm.org/detail.cfm?id=3212479 https://queue.acm.org/detail.cfm?id=3212479
- youruncle 3y ago[dead]
- weebull 3y agoAgreed, and I wonder if we'll see the adoption of "security hardened" CPUs which sacrifice performance features for non-exploitability. You can have one or the other, but not both.