File: intel bug.gif
tl;dr: There is evidence of a massive Intel CPU hardware bug (currently under embargo) that directly affects big cloud providers like Amazon and Google. The fix will introduce notable performance penalties on Intel machines (30-35%).

People have noticed a recent development in the Linux kernel: a rather massive, important redesign (page table isolation) is being introduced very fast for kernel standards... and being backported! The "official" reason is to incorporate a mitigation called KASLR... which most security experts consider almost useless. There's also some unusual, suspicious stuff going on: the documentation is missing, some of the comments are redacted (https://twitter.com/grsecurity/status/947147105684123649) and people with Intel, Amazon and Google emails are CC'd.

According to one of the people working on it, PTI is only needed for Intel CPUs, AMD is not affected by whatever it protects against (https://lkml.org/lkml/2017/12/27/2). PTI affects a core low-level feature (virtual memory) and has severe performance penalties: 29% for an i7-6700 and 34% for an i7-3770S, according to Brad Spengler from grsecurity. PTI is simply not active for AMD CPUs. The kernel flag is named X86_BUG_CPU_INSECURE and its description is "CPU is insecure and needs kernel page table isolation".

Microsoft has been silently working on a similar feature since November: https://twitter.com/aionescu/status/930412525111296000

People are speculating on a possible massive Intel CPU hardware bug that directly opens up serious vulnerabilities on big cloud providers which offer shared hosting (several VMs on a single host), for example by letting a VM read from or write to another one.

Summary article: http://pythonsweetness.tumblr.com/post/169166980422/the-mysterious-case-of-the-linux-page-table (a bit outdated, follow @grsecurity, @scarybeasts and others on Twitter for up-to-date info)

This is going to make headlines and will probably be the worst hardware bug in years.

File: azure reboots.jpg

Microsoft is sending emails about planned Azure VM reboots on early January (see pic).

Some more links:

https://news.ycombinator.com/item?id=16046636 Hacker News discussion
https://lwn.net/Articles/742404/ Kernel page-table isolation merged in unusual conditions

Real-time tweets about it:

So does this impact home users in any way? I run VMs for testing out my software and I'm using Fedora as the host OS. What now? Am I going to take a massive performance hit when using these VMs? I use them locally and I don't have any remote access to them set up. Does this impact the overall performance when using the host OS?

Really, what the hell? I'm about to buy one of those POWER9 workstations. They're expensive but I'm willing to pay more for shit that works.

You won't be affected as long as your VMs are isolated.
But anyway, buy AMD.

>as long as your VMs are isolated
And what does unisolated means ? How do you check that ?

AMD also has backdoors (though it's a TrustZone implementation, aka not designed by retards at Intel).

Apparently it might be related to speculative execution:
>The AMD microarchitecture does not allow memory references, including speculative references, that access higher privileged data when running in a lesser privileged mode when that access would result in a page fault.

Some people are saying it might be related to this: https://cyber.wtf/2017/07/28/negative-result-reading-kernel-memory-from-user-mode/

Basically, Intel CPUs might speculatively execute privileged instructions from unprivileged code, and the results can be obtained via side channels even if the speculation was wrong.

If you use an Intel CPU, then Linux PTI/the equivalent Windows fix will be active and you'll take a significant performance hit. It seems you'll be able to disable PTI through a kernel flag in Grub for example: https://lkml.org/lkml/2017/12/27/145

But it might affect you even if you aren't a cloud provider. For example, mere JavaScript code executed in the browser could read/write kernel memory (and basically pwn you).

File: 1500001712212.jpg

PSP is a TrustZone implementation, it's much less of a risk than Intel's retardation because multiple vendors use it thus making ARM give a fuck about it.

>Urgent development of a software mitigation is being done in the open and recently landed in the Linux kernel, and a similar mitigation began appearing in NT kernels in November.

Wait a sec. Which Asrock boards have been updated with agesa? The x370 taichi is still stuck on using bios 3.20.

Different anon, but can you go into more detail? I've been thinking of getting a ThinkPad and the constant news of security fuck ups form Intel make me wonder if I should save up and buy a Ryzen powered A series.

>It's still untrusted hardware that's tampering with the boot process in ways that it shouldn't, so I'm not thrilled about it.
well there haven't been as many stories about AMD fucking up the security of their processors and between the two AMD's much more likely to open source PSP, as remote is that would seem right now. Both companies should at least be showing the source code, if not publicly, to independent researchers.

>AMD's much more likely to open source PSP
They will NEVER, EVER do that until hyperscale or goverment buys their CPUs.
But they do allow disabling it on some boards right now.

File: concerned.png

Well, Brad Spengler and Chris Evans are reputable security experts and they were discussing it, so I thought it would be a good recommendation to point that out. Advertising wasn't my intention.

File: 1503422517558.png

File: image.jpg

File: concerned.png

>> No.64098708

Is there a list of processors affected by this bug, and the performance hit they will take?

>> No.64098713

Looks like everything remotely recent Intel.

>> No.64098732

Dude, this is not *bad*.
This is "TLB bug"-tier catastrophe.

>> No.64098748

g-guys is it happening?


>> No.64098752

>>64098708 It's been said that it can decrease performance by 50%.

>> No.64098762

Guys, is this really the happening that takes down intel?

>> No.64098885

Has nothing to do with /pol/ you sperg.

>> No.64098936

speaking of apple. grsecurity is reporting a performance hit on intel processors by almost 1/3rd. apple is already under fire for limiting the performance of their phones because muh battery, what happens when they limit the cpu speed for normies macbooks?

File: jtx8w7r7ke701.jpg

which do you think will cause more of an issue, normies whining that their 4000$ facebook machine doesn't load 1000x compressed jpgs or shit rags like motherboard/vice posting an article that apple ignored a security vulnerability in macos kernel?

Based Brad

This feels like the World War Z movie where Israel knew about the zombie attack before everyone else and built the wall

>> No.64099269

What's the likelihood Intel will be forced to recall their CPUs and replace them for free? 35% performance penalty seems way too big to not issue a formal recall.

File: 1506951499958.gif


Intel once recalled Pentium over a bug.


File: 1499456210248.png

Fucking Brad and his ilk are the cancer that are ruining the dreams of a secure linux kernel. Don't believe this fucking bullshit. It's a fucking publicity stunt after all the bad press his toilet firm grsecurity has been going through lately. Don't believe me? Look for yourselves:


File: 1514841009781.png

Are you sure? I imagine Amazon, Google, and Oracle would love to sue for billions.

>This is bad: performance hit from PTI on the du -s benchmark on an AMD EPYC 7601 is 49%

Does this mean AMD processors are affected too?

>> No.64099444


File: 1513041769851.gif



Does anyone know the exact date of the embargo ending? I plan on shorting $INTC

Is this Y2K18?

>> No.64099803

is this the year of the rake for intel?

File: rzoi6cq5d0ux.png

File: rzoi6cq5d0ux.png

It's a program/application/app or whatever you want to call it that runs on a computer. Think of it as king of programs. It's the most powerful program because it makes your hardware like your mouse or webcam work correctly and it can manage other programs like your web browser. If the web browser is taking up too much space in memory, the kernel can decide to kill that program to make sure that the computer doesn't encounter errors. The kernel is smarter than you because it knows how many Chrome tabs are too many.

File: CuxsChqUkAEwWRH.jpg

glad to know /biz/ is not suffering alone

avatar fagging is a sitewide issue too

How do you patch a hardware bug without a recall?

File: itkeepsgettingbetter.jpg

File: feelsgoodman.png


Did you miss EBYN's launch? Literally every hyperscaler is using it

>> No.64100361

It means that AMD CPUs aren't affected. People will need a lot of x86 CPUs wayyy before ARM support is sufficient to replace x86. Which means it's better to invest in AMD than ARM right now.

the REAL volatility will come when the embargo is lifted and some SV soyboy makes a fancy webpage with a cutesy logo about the issue and every CTO in the world sees it

Why not? It sounds as if this bug will allow javascript malware to break of the browser sandbox and the patch causes a sizable performance hit. I don't want an intel processor anymore.

>> No.64100515

I would short Intel and buy ARM/AMD if I had any spare cash sitting around. Gotta see if I have anything I could sell to get on this. The CEO selling so that he has the minimum required amount of stocks when the company is at an all time high and expected to go up is a massive red flag.

It's all but confirmed also trips of truth >>64100555

So every device that currently has an intel CPU will be obsolete now?

Can you link me an archive or article that confirmed the intel anons "leak"? Trying to be as fair as possible here despite the situation.

File: 1513523369541s.jpg

>intel doesn't do shit for a decade
>gets fat and lazy, massive firmware and hardware level security bugs abound
nice job international jewry

The concern was raised outside of a 4chan LARP. If you're interested, just educate yourself on it's existence and it's largely undocumented purpose instead.

I cannot really even imagine a better rootkit

Luckily you can now cripple it: https://www.youtube.com/watch?v=JMEJCLX2dtw

AMD doesn't need PTI enabled.

>> No.64100965

PTI is the fix for Intel's issue, AMD doesn't need it. See this link from the OP: https://lkml.org/lkml/2017/12/27/2

File: 14092465.jpg

Do you even read? From the OP: https://lkml.org/lkml/2017/12/27/2

AMD is not affected.

that's it, intel is finished

>everything shit itself from top to bottom
>incident tickets everywhere

Looks like Pajit will need to do the needful.

File: 8700k-cinebench-nt-production.png

Guys, you aware than won't affect only servers, right? Lots of NAS manufacturers uses Intel CPUs. Some of them have multi-tenancy functionality, like NetApp Storage Virtual Machines for example. If suddenly NAS box would loose 30% of its performance it would be a disaster.

File: brainlet detected.jpg

The linux fix marks all x86 CPUs, except AMD's, as insecure.

>PTI is simply not active for AMD CPUs
>Microsoft has been silently working on a similar feature since November
Pretty much sure Microsoft will fuck the shit up for AMD CPUs too because they can't fucking do things properly. Well at least you can ignore the update.

Intel didn't make any major changes to their microarchitecture since sandy bridge. But regarding this specific problem, I suppose it comes from at least pentium 2, probably even older designs.

The only problem is that apple's benchmarks are incorrect and misleading.

Will this have a performance impact on native programs or only VMs?

a fitting end to a shitty company

Search for "C2000 bricked"

The Xeon marketing blunder was hilarious.

>> No.64101931

AMD - 40 pages talking about performance, features and market conditions of EPYC

Intel - 20 out of 40 pages talking about EPYC, glue and self-fellation.

3 month later release a CPU with AMD component glued.

Wasn't it $2100 MSRP? i hope you know $ ==€ according to how they convert prices.

And it's sold outy tough luck if you expected regular prices from hardware in too high demand

> 4000$
> the meme price keeps going up
> putting the dollar sign after the price like a yurotard

>> No.64103852

Well NASDAQ is up, let's see if it got to them

