4 ms·
This could be a case of survivorship bias - we don't know how many spectre-like bugs did get patched, because they never made it to the public
by infinityio 3y ago
This could be a case of survivorship bias - we don't know how many spectre-like bugs did get patched, because they never made it to the public
- hinkley 3y agoOr the problem could be with methodology, and the wrong people are in charge of the right people left, and so the mindset for testing is just wrong. Also you’re dealing with a company that has been running to stand still for a long time. There’s been a lot of pressure to meet numbers that they simply cannot keep up with. At some point people cheat, unconsciously or consciously, to achieve the impossible.
- BeeOnRope 3y ago> Also you’re dealing with a company that has been running to stand still for a long time I'm not just talking about Intel, but also Arm and AMD. As far as I know none of these has obviously been making proactive Spectre fixes.
- BeeOnRope 3y agoI considered this, but we have pretty good evidence that the chipmakers have not been busily secretly patching Spectre attacks: 1) Microcode updates are visible and Spectre fixes are hard to hide: most have performance impacts and most require coordination from the kernel to enable or make effective (which are visible for Linux). There have been a large number of microcode changes tied to published attacks and corresponding fixes, but no corresponding "mystery" updates and hidden kernel fixes to my knowledge which have a similar shape to Spectre fixes. It's possible they could wait to try to bundle these fixes into a microcode update that arrives for another reason, but the performance impacts and kernel-side changes are harder to hide. 2) If this were the case, we'd expect independent researches to be at least in part re-discovering these attacks, rather than finding completely new ones. This would lead to a case where an attack was already resolved in a release microcode version. To my knowledge this hasn't really happened.
- mabbo 3y agoYou don't need to patch the errors found during the initial R&D. The patch was made before the hardware was ever sold. What's left are the attack vectors that Intel's greatest minds didn't discover.
- BeeOnRope 3y agoThat's true, but it leads the odd assumption that the vendor managed to fix N side-channel attacks before release but 0 thereafter, while random individuals fixed M thereafter over a period of years with N >> M. This seems to be much less likely than the conclusion that vendors are not in fact fixing many prior to the release and then stopping "cold turkey" after that. Especially since these attacks seem to cross chip versions, in many cases 6+ generations of chips: if vendors had substantial and increasing efforts on new chip versions they'd also be catching issues that applied to old released chips as well. We don't see that happening.
- Panzer04 3y agoIf a bug is not known, most of the incentives to the vendor are to not bother investigating, I suspect. You could spend arbitrary amounts of time looking for these bugs and find nothing. Simpler and easier to offer a bounty or something and fix it then. If no one publicly finds the bug it doesn't matter to the mfg (and it wouldn't surprise me if there's truth to your supposition that they know about the bug but wait to fix until someone reports it - no public backlash so long as the bug is unknown) Fixing bugs prior to release seems easy and free, though, especially since many more eyes would also be on the "new" in progress architecture, and proper hardware mitigations that don't cost a lot of performance can be made.
- skolsuper 3y agoWhat about the incentive to release "the most secure chips on the market", are you discounting that a bit too much? Granted that human nature tends to mean these factors don't have a high enough weight, e.g. it's not the safest airplanes that sell the most, it's the cheapest ones that meet the regulations, and the regulations drive safety improvements, for the most part
- api 3y agoWe also don't know how many are still out there unreported and part of the secret zero-day caches of various intelligence agencies.
- thumbuddy 3y agoThere's probably thousands if not more. The way I always imagined this working was. agency and company work together to leave gaps in our hardware and software under the ruse of "it must be secure enough for our use." Agencies get a preemptive six months or so to find enough zero days to do what they want. The engineers at the company screaming about the issues are ignored. Eventually a foreign adversary or domestic hacker finds one that can cause a lot of harm. As soon as they find one a DOD funded student simultaneously discovers it. Alternatively, if documents leak showing how these exploits could happen, same scenario. Not to say all bugs are known, but I'd imagine a fair deal of them certainly are.