6 ms·
Unexpected Page Fault In Virtualized Environment Advisory
- zelon88 7y agoSomeone should make a graph quantifying the number of "mitigations" and performance impacting patch work for popular Intel SKU's since release. It would be interesting to see how many times they've patched the same processor and how much slower they are now than when they were made due to all the mitigations.
- kardos 7y agoIt's workload dependent, so you're asking for a series of graphs. Not a small ask... Phoronix has a bunch of articles where they do this but they are on a per-mitigation basis as I recall
- freeopinion 7y agoDo you spell "someone" A-M-D?
- olyjohn 7y agoI was under the impression that AMD has their own fair share of these vulnerabilities, too. They just aren't as common in the datacenter.
- sp332 7y agoAMD never had one as boneheaded as Meltdown. Intel keeps having more and more uncovered, and according to researchers who went on the record in the NYT, they are not handling reported vulnerabilities quickly or thoroughly. https://www.nytimes.com/2019/11/12/technology/intel-chip-fix.html https://www.nytimes.com/2019/11/12/technology/intel-chip-fix...
- m00x 7y agoIntel is also the most used processor in the market at the moment, once that balance shifts, more attention will be paid to AMD processor so we'll potentially have more vulns uncovered.
- farisjarrah 7y agoI'm inclined to believe that this is actually the case and not that AMD wrote more secure software. All software has security vulnerabilities, the more eyes on the software the more of them are found.
- JackRabbitSlim 7y agoThis isn't "Software" It's hardware (well both but lets not get too pedantic) and everyone was throwing cache and speculative exploits by the shovelful at both AMD and Intel. AMDs are indeed at the very least, "Less insecure." Way more shit stuck to Intel for one reason. The speed advantage Intel had been lording over AMD (Besides compiler shenanigans) was all the corners they were cutting with there speculative execution, et al. Amazing timing that; AMD closing those benchmark gaps and the mass meltdown mitigations in Intel products... all in the same decade Intel was court ordered to fix their unfair C compiler. Intel's domination is simply over...
- dmead 7y agoIIRC intel stopped doing as much validation like 10ish years ago (so, 2009/2010). it would be nice to see then publish a paper about how those decisions lead into these problems...
- xvector 7y agoIntel willingly admitting mistakes is just about as likely as hell freezing over
- teamsforlinux 7y ago
- dreamcompiler 7y agoThe inverse question is relevant as well: How many performance enhancements over the last 10 years were only possible because Intel ignored security?
- bonzini 7y agoThis seems like the usual processor erratum causing potentially very bad things, but only in very rare conditions that no one really understands. It's not another L1TF or similar.
- monocasa 7y agoHence why we need open source CPUs pretty badly.
- vajrabum 7y agoI'm pretty sure that high performance open source CPUs will have their own obscure problems. Too much complexity, too many dependencies, too many possible feature interactions.
- MayeulC 7y agoThat is undoubtedly true, but at least you will have more engineers that are able to dig into them to identify the root cause of these behaviours and fix it. If you are badly impacted by a bug and no one else is, you are the only one with an incentive to find and fix it. You might pay the CPU manufacturer to share the incentive with them, but you'd need quite deep pockets for this. I wouldn't be surprised if widespread open source CPUs also had better debugging tools at their disposal.
- ddtaylor 7y agoAt least with an open source one more than a handful of engineers at a single company could work on the problem.
- thu2111 7y agoIs that actually better in this case? Intel found the issue internally. Nobody knows what it is. The advisory isn't sufficient information to figure it out. People can patch at their leisure, fairly sure that nobody is about to pop up with a 1-day exploit for it. With an open source CPU, by now someone would have looked at the commits that fixed the Verilog/microcode, figured out what the bug is, and there'd be a convenient command line tool to get root on the hypervisor uploaded to GitHub within an hour. This is one of those times when from a practical perspective proprietary seems to win.
- strstr 7y agoAnyone know what conditions are required? The advisory is sparse on details. The errata lists the same vague info: https://www.intel.com/content/dam/www/public/us/en/documents/specification-updates/xeon-scalable-spec-update.pdf https://www.intel.com/content/dam/www/public/us/en/documents...
- erk__ 7y ago>November 2910 They seem to have gotten information about the bug from the future :P This could also show that trhey released it in a hurry since they did not fix that typing mistake.
- rossmohax 7y agoIntel now runs bug bounty program with up to $100k payouts (https://www.intel.com/content/www/us/en/security-center/bug-bounty-program.html https://www.intel.com/content/www/us/en/security-center/bug-...), where one of the requirements is not to leak vulnerability details.
- cortesoft 7y agoIsn't that a pretty standard bug bounty requirement? The idea is that you submit the bug to the company and they fix it before it is disclosed.
- throwawaymath 7y agoIt is standard in the sense that it's not uncommon. But about as frequently it's not a requirement. Many companies allow complete or partial vulnerability disclosure once resolution is complete. It's often on a case by case basis and requires approval.
- cortesoft 7y agoOh, I thought that was what you meant (until resolution).. didn't realize they block disclosure forever
- bdibs 7y agoThere seem to be quite a few security updates today from Intel: https://www.us-cert.gov/ncas/current-activity/2019/12/10/intel-releases-security-updates https://www.us-cert.gov/ncas/current-activity/2019/12/10/int...
- ysleepy 7y agoSkylake and newer. Is Broadwell and before not affected or are those not mentioned since their support cycle has ended? I'd be surprised with Intel spinning up Haswell production for lower grade CPUs on 22nm, but I can't be sure.
- _Codemonkeyism 7y agoIt feels like the only mails I get from DigitalOcean are about Intel processors.
- _Codemonkeyism 7y agoIntel feels so much like Boeing now.