3 ms·
The Volkswagen scandal is beyond the pale. It is genuinely difficult to understate how catastrophic it was for the company. To this day ex-CEO Martin Winterkorn
by SubjectToChange 3y ago
The Volkswagen scandal is beyond the pale. It is genuinely difficult to understate how catastrophic it was for the company. To this day ex-CEO Martin Winterkorn is wanted for charges in the United States.
As for Intel it’s difficult to judge without knowing how complicit they were. The fact it took years to for a proof of concept of Downfall to surface lends some credibility to their choices. Moreover equating a security vulnerability to being outright defective is overeager, to say the least. If that were true then you might as well sue the vendor of any lock that has been successfully picked, cut, shimmed, or broken.
- zmgsabst 3y agoThe difference between Intel and lock manufacturers is honesty. Lock manufacturers will tell you how resistant their products are to particular attacks, eg being drilled out. I wouldn’t say Intel sold defective products if they were honest — and said that speed ups came at the cost of chip level security. But they didn’t. Do you believe that Intel would have sold as many chips if they’d been honest — “our products are faster than before by trading your security for speed”?
- formerly_proven 3y ago> Lock manufacturers will tell you how resistant their products are to particular attacks, eg being drilled out. Most padlocks you can buy in Home Depot can be trivially bypassed in at least one way (typically shimming, often also vulnerable to comb picking or reaching through the core); virtually all wafer locks are highly susceptible to raking and can literally be opened with a paperclip. These are akin to admin/admin credentials. Physical security is an absolute joke most of the time compared to software security.
- SubjectToChange 3y agoI wouldn’t say Intel sold defective products if they were honest — and said that speed ups came at the cost of chip level security. But they didn’t. The trade off between risk and performance isn’t a smooth gradient in this case. Eventually conservative behavior under a certain threshold does nothing but cost performance and waste power. Therefore, the multi-billion dollar question is where that threshold is and how closely can a design toe that line. Perhaps I am wrong, but I don’t believe Intel’s management would risk a vulnerability like Downfall for better SIMD benchmarks. Do you believe that Intel would have sold as many chips if they’d been honest — “our products are faster than before by trading your security for speed”? Outside of the “prosumer” market, the vast majority of retail consumers do not even look at CPU benchmarks, nor could they understand them if they did. The true target of those performance numbers is the enterprise segment, a reoccurring multi-billion dollar revenue stream for Intel. With that in mind, it makes about as much sense for Intel to ignore vulnerabilities for benchmarks as it does for a milkman to sell spoiled milk.