File: 15 KB, 350x200, emergency.jpg
64130690 No.64130690

UPDATED: this is way bigger than previously thought. Apparently there's more than 1 vulnerability. Intel is the most severely affected and KPTI (performance-degrading fix) is only for them, but there are other security bugs which affects everyone (including AMD).

1) The #IntelChip is only one piece of a much bigger security problem. There are two critical security flaws in microprocessors. The first, called Meltdown, affects virtually all Intel microprocessors.
2) The second, dubbed Spectre, is a design flaw that affects virtually all modern microprocessors (not just Intel, but AMD and ARM) and has NO PATCH.
3) Meltdown presents an urgent crisis and administrators need to implement the KAISER patch ASAP (even though it will slow performance speeds by as much as 30%), but the Spectre flaw is far more pervasive and will require a complete rearchitecture of virtually all microprocessors
4) Spectre is harder to exploit, but has no easy fix, and is far more pervasive. Researchers say it is highly likely the threat from Spectre will be with us for the decade to come.
5) The basic issue is age old security dilemma: Speed versus Security. For the past decade, processors were designed to gain every performance advantage. In the process, chipmakers failed to ask questions about the security fundamentals of their design.
6) Now, Meltdown and Spectre, show that it is possible for attackers to exploit these design flaws to access the entire memory contents of a machine. The most visceral attack scenario is an attacker who rents 5 minutes of time from an Amazon/Google/Microsoft cloud server and...
7) ...is able to access the programs and data off every other Amazon/Google/Microsoft customer renting space on that cloud. That means logins/passwords/SSL keys/files/the motherlode.

8) The business/economic implications are not clear, since eventually the only way to eradicate the threat posed by Spectre is to swap out hardware. It's not clear there is even manufacturing capacity for this. It is also unclear who will bear the cost (chipmakers or customers).
9) The industry will be dealing with this for a long time to come. END.

- https://twitter.com/nicoleperlroth
- https://twitter.com/tomwarren/status/948674110795800577

1st if true

So will there be lots of cheap second hand cpus flooding the market?

File: 77 KB, 953x535, INTEL.png


There are three risks

Google blog post: https://security.googleblog.com/

File: 87 KB, 951x531, 2018-01-03-222850_951x531_scrot.png

>h-how do we implicate everyone in this
>we need everyone to help! it's not just us!
>t-the processors are working to spec anyway

I just wanna watch the CPU's burn. I cancelled my order for a new PC. I'm going to wait this one out untill it's fixed.

gonna have to wait a while bud

You can tell they knew about Meltdown all this time and prepared the announcement of Spectre together with it just to make Intel sound less worse.

>side channel attacks have existed for a decade or so
NSA was working with them in 1955

>it's not an issue with our product


>Intel getting BTFO with the kernel exploit
>Drops news of second "flaw" it has been saving for this exact moment
>Instead of just them burning now everyone is in the same ship
>Original kernel exploit no longer a big worry

Smart move

Power8 master race

ahh sheeeeeez.

Who are you quoting?

Time to install temple os

CPUfags on suicide watch!

>(including AMD)

Incuck lies.

Intel exec on the investor pacification call

Pajeet openly asked them whether it affects AMD or not and they bluffed for 5 minutes and then outright lied when he followed up

I for one am glad intel dragged amd down with them :)

Daily Reminder that silicon fabrication and production is organised years in advance. Intel's next 2 entire gens will still have this issue.

The CEO bailed. When the pilot is ejecting out of the roof with his briefcase and parachute, you know what's going down.

We're about to see a repeat of Seagates spectacular fall from supremacy to Western Digital circa 2008

Are the glow in the dark CIA niggers behind all this?

>These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running them.



LOL GayMD is fucking finished for fucking lieing about this!!!

>2) The second, dubbed Spectre, is a design flaw that affects virtually all modern microprocessors (not just Intel, but AMD and ARM) and has NO PATCH.
>dubbed Spectre
As in its a ghost, it doesn't exist, Intel just threw this in to cover their ass.

>as we see it we don't expect any financial impact
>I wouldn't expect any change in acceptance of our products

Yeah, absolutely tons of secondhand server hardware that's insecure for cheap.

Holy fuck you could build server-class home NAS for the price of an NAS today

>until it's fixed.

probably true.
But it actually doesn't evem matter. it's ogre now.

What does this mean for me an average poweruser who only uses his desktop rig a few hours a day for gaming and windows optimizations?

Does that mean the apple chips in the ipads are good to go? Will Apple have an advantage?

CIA niggers are incompetent hacks. You mean NSA niggers.

literally nothing, don't update

Enjoy your nocomputer for the next 5 years. You can't fix this shit, they've been cheating all this time by having this insane flaw that allowed them to stay faster than the competition

This is tearing down the tower and rebuilding from scratch, not a quick remodel

If you connect to the internet you will have your PC host to a Pajeet coinmining operation

nothing. but the porn site you go to and companies that run your online games are about to get assraped.

Oh fuck

And this is why I only use Allwinner CPUs. With the Chinese CPU we are all winners.

crap crap crap.
they've outsmarted us.

Spectre is already getting patched.

What about for laptop users?

This will result in many newcomers competing and innovating while the price lowers and performance soars right?

Cucks will have to downgrade from 4k to 720p blacked.com vids?

what the fuck? i just read how amd said all 3 variants don't affect them?? who do i trust?


>To take advantage of this vulnerability, an attacker first must be able to run malicious code on the targeted system.

> locally executed
> still can't modify memory

really makes one ponder

you couldn't handle one night and most of a single day of butthurt, could you?

As they said many many MANY times, "average users" won't see any effect locally.

But the websites you use are high-impact and will either become creakingly slow or have to reduce service or quality significantly to cope

THE IMPORTANT part is that the Meltdown fix incurs a huge performance loss, who the fuck cares about this Spectre meme?

It's going to be my very first top of the line gaiming PC. I don't mind waiting for an extra year for some i7 9700k (fixed) and GTX 1180/2080


I hope so

>> No.64131016


pathetic inshills

Where is the list of Intel CPU's it effects? I see "Modern" but how far back are we talking? Skylake? Devil's Canyon? Sandy Bridge? Core 2 Quad days?

Why doesn't IBM take advantage of this?

>lol they can't change your passwords, just read them

Are you stupid or just retarded?

Intel GPUs have HEVC Main10, VP9 10bit and H.264 hardware decoding up to 8K res from Kaby Lake onwards

>> No.64131032

>> No.64131042

man if they're lying about AMD... well I wouldn't put it past them

Pentium 2 onwards

Early 90s

>> No.64131045


> absolutely tons of secondhand server hardware that's insecure for cheap
sell BTC

pentium pro

>> No.64131052

All x86 since the 90's.

>only uses his desktop rig a few hours a day for gaming
Pick one.

yes. or increased ads or cost to use.
are fucked? we are talking cdn.

>> No.64131072


What if they just lowered their dividends?

>You can tell they knew about Meltdown all this time

They truly aint shit.

These numbered points didn't come from the Intel conference call, which has just finished, it's from some cunt who writes for the Verge and quotes no source. No indication where the details, let alone the names came from. Chances are the exploits don't even have names adn he's made them up himself, like those cunts who hyped up a minor issue a year or so ago, called it a scary name like badlock and started a viral campaign to raise awareness of it unnecessarily.

>> No.64131080


They're decent names though.

How do we know PowerPC isn't affected?
It may just be untested due to lack of machines to test on.

>> No.64131092

They have names, but the names are
>Bounds Check Bypass
>Branch Target Injection
>Rogue Data Load


I love how this is a blatant attempt at damage control on Intel's part.
>oh fuck this security flaw is really an issue
>oh fuck the patch just makes it worse
>what do we do?
>I got it, we make up some bullshit that effects EVERYONE so it can be a team effort to fix everything and not just a failure on our part.


what about Power Processors?

We've been fine for 40 years without this problem, how bad can it be. Plus it only affects the CPU it's just billions of ones and zeroes why would anyone want to hack them?

>> No.64131106

True, with that chip you already KNOW it has a state-controlled backdoor in it. No need to wonder.

>>64130690 So we will just go back to good ols dedicates servers and shared hosting. It's no the end of the world. Dumb normies would pay all the extra expenses anyway.

>> No.64131108

I'm sure some burgers believe this.

I'll give you that, spectre is cool. Meltdown is too obvious in a shit made for TV hacker movie kinda way

>The issue is now being called "Meltdown and Spectre" with the bug description up at SpectreAttack.com.



I'm glad to see the end of computing. Time to get out my Itanium Server.

>> No.64131120

The funniest part is how we will be seeing servers being compromised by this shit for decades because no one ever updates until it's too late, just look at the wannacry meme that only affected ancient WinXP systems.

>> No.64131121


If it takes them 5 years to fix it, they might as well call it a day and go bankrupt. They will work like crazy to fix this ASAP

>> No.64131127

What the fuck is this I just take a day to enjoy seeing someone still use Windows XP and there's all this shit going on

So effectively if you're using a computer or a smartphone you're buttfucked or what now? Have we come to the point where, maybe by 2025, people will stop using technology or something? I don't know what the fuck is going on anymore...

pic related.
what a wild ride.

Time to dust out my trusty 22mhz computer from 1990

>> No.64131140

Speculative execution has been a feature of pretty much any architecture worth a shit for decades. The only reason POWER wasn't mentioned is because nobody gives a shit about it.

>> No.64131143

They're patching, but that will fuck performance.

Replacing the chips they've been using for 20 years and that have been then only thing keeping them ahead of the competition isn't quick or easy

>> No.64131148

... which he clearly thought weren't dramatic enough. Rogue data load is the only which probably sounds a little menacing to the layman due to the word rogue.

>> No.64131158

They don't have the capability anymore. They don't make anything. IBM really isn't relevant anymore. They're just "idea"-guys now.

They do have the new Power chips I remember reading about some time ago. Sadly, they've already abandoned the field to Intel, much like AMD did.

Terry was right when he said Intel were CIA niggers trying to shove as much bloat on their silicon as possible.

and still, their back up plan backfired.

Then they'll call it a day and accept their huge losses. Time for another player (AMD) to be the champ.

Your mom enjoys rogue data loads every night.

>Have we come to the point where, maybe by 2025, people will stop using technology or something?
Exactly what the people at (((The Top))) want to see.

I fucking hate all the noise from corporate cocksuckers. So much mis-information from people spamming their favorite company won (they do it for free btw) is causing confusion for people who really need to understand this issue is tied to many modern CPUs from all ISAs

If you believe everything a corporate entry says on this matter for the time being then you need to remove the cock from your mouth before you pass out.

>> No.64131188

Yeah, just like intel

Can't abandon a field you never played on, mainline POWER chips were never made to compete with Intel offerings on the consumer market and IBM never wanted them to.

>> No.64131199

I was, for like 5 seconds until I checked the sources.
but you? you're still fucked.

I take this back, I see that the guys who claimed the bounty on it named them that. I guess they are entitled to do so.


A hivemind civilization wouldn't have this problem.

None of this would have happened if there were more women in technology.

>> No.64131206

> While the performance heavily depends on the specific machine, e.g., processor speed, TLB and cache sizes, and DRAM speed, we can dump kernel and physical memory with up to 503 KB/s.

>> No.64131219

You hate differing opinions? Are you mad that you made a mistake?

>> No.64131223

Even the men look feminine what is this shit

>> No.64131224

>Yeah I-I may still be a bootlicker but so are you!
ARMlets do it again.

>> No.64131225

>> No.64131226

AYYMD is lying as usual

Lied about Barcelona performance & TLB bug

Lied about Vega performance and power efficiency

They are lying about the vulnerability not affecting them, you can't trust these liars

intel is dying before our very eyes

>AMD prices begin to climb

oh god no

So this has been a thing for years and nothing has been affected.

Exactly. You know for a FACT that AMD probably has everyone running on all cylinders looking for any sort of flaw in Ryzen. Anything that can come and bite them in the ass down the road. Especially since all of their future chips are built on gen 1 Ryzen. Threadripper, EPYC, Ryzen+, Ryzen 2, etc.

>> No.64131243

All Intels are fucked by Meltdown, fix reduces performance up to 63% depending on workload and model.
AMD doesn't have this vulnerability.
That's all you need to know.

Whats spectere and how can they fix it. Will it also come with a profirmance hit

>Hey Prash, we're taking pictures for the website could you come over here?
>Yeah gimme one sec to put on my sunglasses, you mind taking my picture while I'm screaming?

t. amd fanboi

This is what you cucks get for about buying an macbook

There has been thousands of hacks that was probably caused by this

Now that everyone knows about it there will be even more

Amd shills are delusional. They think amd is their friend and they can trust them

>> No.64131274

Bottom left isn't so bad
He's fat but I'll take a fatty over some little twink soyboy

What is the difference between Spectre and Meltdown?

It's some irrelevant noise brought up by Intel to distract people from Meltdown.

>AMD statement:
"None of these attacks work on our chips."

Well. Time to go back to AMD.

where did 63% come from

Join us now and free the software
You will be free hacker you will be free

Fucking wrong retard it is fucking 5% at best gaymd shill.

Understand that EVERYTHING is fucked from grandma's CompaQ to macbooks, to servers, to gaming powerstations

Both Intel and AMD are trying to damage control the fuck out of this shit. Do not trust either or become nothing but a low intelligence person who shouldn't be allowed to reproduce.

>> No.64131300

Recording of the Intel call for anyone who missed.

>> No.64131302


>trusting intel

Not even ONCE!

Ya'll fuckers need to check the catalog

And the slides they refer to


He was lying, it's closer to 80% in I/O tests.

>> No.64131325


Please, upload the collection. :3

more convenient format.
this will be reposted a lot I reckon.

This is a happening, anon, this isn't some fucking chink shit general

First it was 30% now 63%? I'm smelling bullshit.

>AMD literally excluding the fix from their CPUs since it doesn't affect them at all
>damage control

The truth is:

>some ARM64 designs are affected by this same flaw
>AMD is one source manufacturing these ARM designed cores
>intel implies that AMD is affected by this bug

The security flaw DOESN'T affect AMD x64.

>> No.64131344

>mfw Socket 7 Pentium (the newest CPU unaffected by all of this) skyrockets in price
>happen to own five MMX 200 chips for no discernable reason

>> No.64131355

Literally fake garbage paid for by gaymd

>Has Meltdown or Spectre been abused in the wild?

>We don't know.

>> No.64131364

7 Pentium is affected

La Productividad Extintor...

Best meme of week

on the bright side, I'm so glad I'm not a sysadmin for any company right now.

isn't it possible for them to implement a more efficient patch later on which speeds up the processor again?

>> No.64131396

I'm willing to bet money they knew all along what this exploit is/was. Maybe even intentional. How do you think FBI/CIA/NSA gets in? You don't think those agencies actually make their own exploits and backdoors do you?

>> No.64131404

I will not update

All computing devices back to the abacus

Intel shills are delusional. They think Intel is their friend and they can trust them

.10c has been deposited into your account.

>We also tried to reproduce the Meltdown bug on several ARM and AMD CPUs.
>However, we did not manage to successfully leak kernel memory with the attack described in Section 5, neither on ARM nor on AMD.
>neither on ARM nor on AMD.


honestly lost all interest now that I know kiketel isn't the only one getting rekt. I only cared about this because I thought it would mean kiketel would finally burn to the ground.

Wannacry affected unpatched Windows 7 and Server 2012 systems as well.

Aw shit

There's no efficiency to be had here, the fix literally disables the functions that are vulnerable and offloads them to a slower but safe system, there's no way to actually fix it through software.

>> No.64131438

We knew they been knew.

>> No.64131447

Opterons are affected?

this is straight from google's project zero

stop making shit up intel babbies

I listened to the conference call:

1. They tried real hard to make it seem like this is just a software attack and that the CPUs are operating AS DESIGNED. Fucking assholes: If the design allows for the attack to happen, then the design is FLAWED by definition.

They're trying really hard to avoid being labeled as "flawed".

2. They completely fucking sidestepped the datacenter workload question. "We don't classify workloads by datacenter or user". They then said "average user workloads won't see a significant impact from the software fix".

Again: kiketel jewing the english language to avoid addressing the real problem: all datacenter servers running intel chips are gonna get impacted.

3. Pajeet asks if they know whether or this is an "industry issue" or an "intel issue". Senior kike officer gish gallops the questioner for five minutes with intel bullshit and FINALLY responds saying "industry issue" after pressed.

In short: Intel is going to become the catalyst for a performance holocaust the likes of which cpu cycles have never seen.

AMD isn't affected.

So I should just change to AMD, right?
I don't have any preference, I think, can I still use Nvidia GPUs with it or do I have to change the whole thing?

>> No.64131483


Someone is going to end up in pieces in a suitcase. They gonna say it's a suicide LMAO

>implying "Spectre" performance hit even exists
>implying "Spectre" even exists

is my gaymin gonna be hit by this performance loss or what

They made it unsafe by design to make it artificially faster. :^)

>> No.64131496

Just wait until someone discovers all the UEFI backdoors

>> No.64131497

What the fuck do I know, I'm just a dumb fucking normie who hates kiketel

I think the last is a regular pentium, even pentium pro is compromised
>released 1993
There are literal adults on /g/ younger than that, just let that sink in

>In short: Intel is going to become the catalyst for a performance holocaust the likes of which cpu cycles have never seen.
So you're saying it's another shoa?

Expect lag spikes if you do multiplayer.

At least i will now get the chance to enjoy every single frame of my games

Around 3% based on a small set of benchmarks. If you do play multiplayer games then that may be a bigger issue for the servers.

Most x64 AMD processors aren't affected by one of the security flaws

>AMD is not susceptible to all three variants
This means they're susceptible to at least one.

nv gpus should be fine as long as you have an amd cpu

Yes it fucking is retarded shill

ARM64 server chips are branded opteron.

>> No.64131518

Sure, Ryzen + GeForce master race is the only true race.

>> No.64131524

Even AMD is affected by this?

see >>64131457

AMD is unaffected.
my cock is hard thinking about how hard they're going to hit the ground. I wouldn't feel this way if Intel wasn't guilty of Jewish trick after Jewish trick. With their shady as fuck business practices and gimped products, I hope they go down.

P5 doesn't do speculative execution though?

>> No.64131528

>> No.64131531

>> No.64131534

Can someone explain to me what is going on? I have been out of it since the 26th of December due to appendicitis and a complication that put me under heavy drugs till this morning.

I'm sysadmin on paid leave right now and I opened my laptop to HUGE amounts of emails, my phones to texts, from other sysadmins and my bosses.

What the fuck is going on?

>fake garbage
>intel ceo lied twice already on live TV today
>he dumped all of his stock
>they failed to drag AMD down with them
>it backfired beautifully, it didn't even last one minute.

Fuck, I'm about to hit platinum in Street Fighter V. Should I really stop?

Isn't this the most serious thing to happen in a very long time?

Ok then, I need some upgrades anyway. Might as well get a new gpu and a new ssd

I hope at least amd doesn't force me to use W10 like intel does.

>> No.64131546

>> No.64131551

Link? Would be useful to counter the pankajtel shills

Feels good being safe.

>> No.64131553

If what you say is true, I swear, I will NEVER buy any Intel product again. This is the scummiest of scum tactics.

Someone finally figured out that the thing that lets Intel processors be better than everyone else is a huge backdoor to access your entire computer via the kernel memory

Intel investor pacification call

Accompanying slides

It will but there are workarounds.

>inb4 AMD turn all smug, market their shit as super secure and price Zen+ shit double
don't do it fags

>> No.64131568

ARM64 is effected, not ARM32

I figure the workaround are the same as the ones for intel

Yep, their literally finished, fix drops performance over 50% LOL!

>I'm sysadmin on paid leave right now and I opened my laptop to HUGE amounts of emails, my phones to texts, from other sysadmins and my bosses.


Tell yer boss to buy AMD next time.

> I'm not dirty you are dirty

Intel mudslinging in progress

huge exploitable flaw in Intel's architecture going back to every single chip they've made for the last 10 years

This makes sense now

People seemed to have gotten over heartbleed quickly

Thank God I have a Ryzen™

and the official report on the Meltdown exploit. The researchers specifically say that the attack didn't work on ARM nor AMD

>> No.64131603

Is the bug happening in long mode only?

>mfw consolefags win again

You all know this is a ploy to buy new computers, right? There's no way they couldn't have found this in my ten year old core2quad this far in the game and for damn sure the slowdown fix is suspect.

>> No.64131608

Yup. This worse than shellshock or heartbleed. It's a huge fucking disaster.

>> No.64131611


>> No.64131612

>> No.64131618

Irrelevant if i don't transmit anything and don't enable JS. No idea why 4chan didn't use https by default, that browser does support it

We won bois!

>> No.64131628

Spectre affects pretty much any CPU which implements spectualative execution.

>> No.64131634

Of course they knew, but nobody else did. That's the point.

Why didn't we listen?

>> No.64131642

But PCID requires 64bit mode

>10 year old
The exploit is more than 20 years old, it's ogre.

Came here to say this, but was too skeered to mention it first.

AMD won't do shit because Intel never lowers prices under any circumstances

>AMD rebukes Intel, says flaw poses 'near-zero risk' to its chips
>"To be clear, the security research team identified three variants targeting speculative execution. The threat and the response to the three variants differ by microprocessor company, and AMD is not susceptible to all three variants. Due to differences in AMD's architecture, we believe there is a near zero risk to AMD processors at this time."

>> No.64131656

so intel insider posted on /pol/ and they didnt listen?

>Shintel processors literally drop to laptop tier hardware

>> No.64131658


data taken from Google's Project Zero

>> No.64131659

odds on cia/nsa being involved with this?

>> No.64131660

Just got an Intel 8400 how fked am I bois?

>> No.64131666

what the fuck

>> No.64131676

they probably were

it helps facilitate the killing of browns

Intel ME is unrelated

Why do we never listen

>implying consoles aren't also affected

>> No.64131688

I'm getting mixed signals here, some say they don't others say they do, any link to prove your statement

>> No.64131689

>> No.64131692

>> No.64131694

more like "None of our chips work"

Is Intel actually lying now? Wtf I don't know what to believe anymore

Because the fix was trivial. This flaw requires gimping performances on Intel for meltdown and fundamentally changing CPU architectures for everyone for Spectre.

>> No.64131700

Google says AMD is definitely unaffected by 2 of three varients and almost certainly unaffected by the third

>> No.64131712

AMD suffers from spectre only. NOT MELTDOWN.

>> No.64131718

More like
Intel official statement:
"our processors are literally laptop tier now"

Damn it man I just wanted to play games

I just really hope nothing is discovered in AMD's architecture. I hope they're not sitting on their laurels waiting. That AMD is actively auditing their own shit.

We don't know about SPECTRE, but the other 2 don't affect AMD

Patches will roll out next Tuesday and it looks like your games and everyday activity on your desktop won't be affected.

/pol/ is a fucking hypocrite for supporting drumpf the kike lover.

Damn Intel is crashing horribly with no survivors

They've probably known this for years

Their entire business in built on lies, you only noticed now because you're paying attention.

See >>64131655
None of bugs affect the AMD CPUs

>> No.64131744

Senior Microsoft software engineer here. Guys, I am trying SO hard to make sure the performance hit affects AMD too, please give me your support to keep the hardware market fair.

Intel has been lying ever since their CEO sold all his stock in December in a totally unrelated event that definitely wasn't because he was told he'd be resigning in early January

Fuck off AMD shills.
I bet you this is 100% exaggerated and doesn't affect anyone.

>> No.64131750


He got a lot of (You)s so I think people were listening, especially since he made it sound like the vulnerability was used to spy on Trump

>not running everything in ring0 anyway

>> No.64131761

save up for a 1200 or 1600, it's basically an unlocked i3/i5 with a different chipset

>guy drops basic pc knowledge and claims to work for intel
>/pol/ laps it up harder than 3 day old jizz off the floor of a truckstop bathroom

Your games will be affected, just not as much as data centers will be.

So if I get this right the biggest problem is not us casual users being affected, instead, big companies.

Pol never listens... it's usually dismissed as "larping garbage"

They are, and from the sounds of it it's similar to the intel one in that it's an architectural problem, but it has no patch and is much harder to execute

top kek

Most websites you use, including this shithole, have Intel hardware

At best they'll run slow, at worst they'll cave completely

>> No.64131784


On an i5 6600k with a GTX 660 on Win7. I probably won't update windows as I haven't updated it in ages anyway.
I was thinking of upgrading to a 1070, but with this news I might go with an RX480

>> No.64131793

you were in denial, you had a glimpse of the light and now you're back in stage 1 denial.

intel is fucking done

>> No.64131795

>Major data center giants like Amazon and Google are concerned enough to be seen publicly asking about potential impact
>Microsoft and to a lesser extent the Linux community is up in arms about rolling out a patch ASAP

How do you function with this level of delusion? Is day to day life difficult?

So malware locally installed on a machine can peer into the cache regardless of firmware and software and be used for corporate espionage?

>tfw we just updated all our workstations

So there are 3 different types of side attacks that peer into the cache, and only amd is immune to 1 of them.

So in this "backdoor" that the 3rd type of attack that only effects intel CPUs was just a huge telemetry function which allowed them to make "better" performance numbers?

>> No.64131802


Guess that damage control on CNBC worked well.

what's stopping them from just changing to intel?

No, they arent.
Google's Project Zero confirmed.
AMD is clean.

IF Meltdown affects AMD there's no way anyone would trust them EVER again. Let's just wish they didn't fuck up.

>> No.64131814
>soon the only safe way to browse the internet will be on your old C64

>> No.64131815

Pretty sure there isn't a Spectre fix yet, so nobody is sure of its potential performance impact.

>> No.64131816

great! i hope they get rid of javascript first.

Know that already. Intel just doing some damage control.

File: 446 KB, 662x1408, intlel tweet.png [View same] [iqdb] [saucenao] [google] [report]


>> No.64131825

Lol, I don't care, my Athlon x64 x2 is still performing well with 8600GT nVidia.

Fucking sigh.

First Heartbleed, then Krackattacks, now THIS?

Maybe I should just give up computing.

changing from intel*

>> No.64131834

The intel ME is a separate processor with it's own OS. It had bugs but they were "fixed" with a firmware update some months ago
>> No.64131835

B-but muh always right
>> No.64131836

Desktop, Laptop, and Cloud computers may be affected by Meltdown. More technically, every Intel processor which implements out-of-order execution is potentially affected, which is effectively every processor since 1995 (except Intel Itanium and Intel Atom before 2013). We successfully tested Meltdown on Intel processor generations released as early as 2011. Currently, we have only verified Meltdown on Intel processors. At the moment, it is unclear whether ARM and AMD processors are also affected by Meltdown.

Which systems are affected by Spectre?
Almost every system is affected by Spectre: Desktops, Laptops, Cloud Servers, as well as Smartphones. More specifically, all modern processors capable of keeping many instructions in flight are potentially vulnerable. In particular, we have verified Spectre on Intel, AMD, and ARM processors.

Which cloud providers are affected by Meltdown?
Cloud providers which use Intel CPUs and Xen PV as virtualization without having patches applied. Furthermore, cloud providers without real hardware virtualization, relying on containers that share one kernel, such as Docker, LXC, or OpenVZ are affected.

>> No.64131847

nigger this is CPU not GPU

TempleOS doesn't have virtual memory either so I guess that's a "modern" "alternative".

they're not lying, just using sneaky linguistic tricks: they grouped together the exploits, one of which affects intel, one of which affects everyone
>Recent reports that these exploits are caused by a “bug” or a “flaw” and are unique to Intel products are incorrect.
and then they mention their competitors in the next paragraph to associate those names with all the exploits, even though their competitors are only affected by one.

>> No.64131853

Online games gonna sucks

The info about ME posted there is from before all the ME vulnerabilities were found, or people even knew what exactly the ME was able to do.

They all affect Intel, one of them may or may not affect aMD.

Only way to patch it is to shut down speculative execution, resulting in nominal changes to "average" user performance but likely to greatly impact companies, data centres and servers as it's "workload dependent".

Basically RIP Intel

A 286 supports arachne browser
You can use that

>> No.64131866

>> No.64131867

>> No.64131869

Maybe you didn't know this but hardware costs money and changing could cause all kinds of issues

>> No.64131873

That shit would be expensive and time consuming. hey'd have to rebuild from scratch

>> No.64131875

>> No.64131878

Yes, these X% benchmarks are just averages to mask what's taking time.
Need hard data.

In worst case, think of real-time data streaming LOB services doing tons of system calls, those will be in for a surprise when amazon reboots...

>> No.64131880

Would have been a good excuse to bring back those i686 distros to life

Are phone posters in trouble too??

Yes but according to the other thread Nvidia GPUs use a lot of syscalls which will suffer from this update, ergo your nvidia GPU gets fucked over too

>> No.64131903

They have been lying a lot longer than that.

Why are those security auditing companies so terrible compared to NSA?

kek, even mads stock is dropping now.

>sitting here on my thinkpad with a third generation intel like

>> No.64131913

>mfw secure browsing will only be possible via tablet or sim free phone for the next 5+ years

>mfw I have no face

>> No.64131918

>> No.64131920

>> No.64131921

>CPUs have been stagnant for years
>PCs keep getting slower since they can't keep up with the software bloat
>now this

>except Intel Itanium and Intel Atom before 2013
I fucking knew it. Buying a netbook with a N270 was the best computing decision I ever made. This shit is rock solid inside and out.

Project Zero's paper on the subject


Would spectre work on current gen consoles? Could it be used to make piracy possible?

Because NSA has more than likely been working hand in hand with Intel utilizing this "newly found" security flaw to spy on people. It doesn't take a shit load of technical know how to break into a building when you have the fucking keys.

>> No.64131943

I won't, but I might as well get an AMD GPU in case I'm forced to update in the future. I'm not gonna purposefully put myself in a risky position like that

None affect AMD64. Stop spreading lies.

>> No.64131949


who else /comfy/ watching this meltdown?

Spectre affects ARM too

Itanium will rice from the ashes like a phoenix!

Holy fuck, he refuses to answer!

In laymans terms, put a lock on your front door - stops people robbing you but makes it take longer and more effort to get in and out of your house, and those going in and out a lot will be worse affected than those who only use the door occasionally.

Up to now you were safe because nobody knew your door was unlocked the whole time.

mark my words, intel is working as hard as they can to find a flaw in AMD chips which they're then gonna give to "security researchers". this news is gonna come out to take heat off intel.

this issue is massive and intel will go to any lengths to reduce the impact.

just fucking watch

MyCPU is safe.
>> No.64131979

how they will push their brainwash without tech?

>> No.64131981


>> No.64131982

provide proof.
This thread is full of "only ARM64 no ARM32" "AMD IS ALSO AFFECTED"
But nobody cites the fucking claims

There goes the dream of ever increasing CPU performance and exponential growth even sooner then expected. It was a nice time /g/
Now we will be stuck in regression for years

it's like a train wreak in slomo

Well rip

Maybe something good will come from this, the harsh cold made the vikings, as they say, or something like that.

>> No.64132003


Which systems are affected by Spectre?
Almost every system is affected by Spectre: Desktops, Laptops, Cloud Servers, as well as Smartphones. More specifically, all modern processors capable of keeping many instructions in flight are potentially vulnerable. In particular, we have verified Spectre on Intel, AMD, and ARM processors.

Which cloud providers are affected by Meltdown?
Cloud providers which use Intel CPUs and Xen PV as virtualization without having patches applied. Furthermore, cloud providers without real hardware virtualization, relying on containers that share one kernel, such as Docker, LXC, or OpenVZ are affected.

What is the difference between Meltdown and Spectre?
Meltdown breaks the mechanism that keeps applications from accessing arbitrary system memory. Consequently, applications can access system memory. Spectre tricks other applications into accessing arbitrary locations in their memory. Both attacks use side channels to obtain the information from the accessed memory location. For a more technical discussion we refer to the papers ( Meltdown and Spectre)

When are chineses going to build their own microprocessors and save us from the kikes?

>> No.64132012

People have been suspicious of ME since it was introduced. Maybe even before. That's what anon meant by "basic knowledge"

File: 310 KB, 580x282, thisisfine.png [View same] [iqdb] [saucenao] [google] [report]

>> No.64132017

>carriers update at glacial pace
time to take all sensitive information off my phone i guess

Well, I refuse to lose that 30% I fucking paid for.

Guess I'll just circlejerk the same websites I do now with JavaScript turned off for the next few years.

I'm not too concerned of your average desktop home user but what about at enterprise level?

Major lawsuit incoming?

>> No.64132033

>> No.64132034

>> No.64132037

Right now I have Intel Core i5-4670K Haswell in an ASRock z87 mobo.
I have a spare AM3+ motherboard (MSI 870A-G54)

It can support an FX-8350 with a bios upgrade (i have a spare phenom 2 to upgrade it first).

Should I pull the trigger and get the FX, or save another $200 for Ryzen 5 and a new mobo?

>> No.64132044
>But have you heard of these side-channel attacks that also fuck our products up?

>> No.64132049


almost, all 3 of them for AMD x86_64, arm_amd has the spectre vulnerability though.

>> No.64132053


For what? The processors are working exactly as their specs say they should. This is a feature, not a bug.

They're only patching it because that feature has a massive security risk attached, but if anyone had bothered to ask they'd have known that from the start. Because as they said, working as advertised

>> No.64132064

they always wanna act like they're the first to find out the truth.

>> No.64132067

>> No.64132073

Anything intel branded faster than 133mhz.
Mhz. That's not a typo.

Pentium Pro and later

>> No.64132076

>> No.64132083

It's easier to hide their lies without it.

for not disclosing the vulnerability is something that can have a case, but Intel will say that they didn't know anyway.

>> No.64132088

>he didn't have a 233MHz Pentium 1
Intel CPU? Yes

>> No.64132091


Take that Brian & Intel shills!

>> No.64132098

>> No.64132108

What chips are we talking about here? I don't know much about server hardware

>> No.64132112

>> No.64132114

>> No.64132115

AMD should hit these fucks with a libel lawsuit, based on whats in these slides.

>apple slow down their phones
>a few weeks later intel slow down their cpus

>> No.64132118

It's actually up to 80% depending on the workload.

What about dumbphone?

except not AMD and ARM, but amd_arm. There's a huge difference.

>> No.64132129

>just Sold a Mini PC with an Atom 330 for 99€
>IT will be worth 5x that by next week

Data centers are fucked the most.

>> No.64132144

Holy shit, is this a blessing in disguise?

lol don't worry they don't give a shit about your vidya

>> No.64132147

Then we nuke the country responsible off this planet

MicroShit patch just came out

Intelfags go get your 30% fix


Javascript is generally not large in size or performance heavy for servers. It's more of a client/browser issue, performance wise.

Am I getting my hopes up too far for thinking this could cause some major damage worldwide?

Is Ronak Intels house Pajeet or something?

That would be so fucking good, if Intel would just flat out admit that US government forced it.

Gotta slow them down so you have some reason to upgrade. Websites can only stress your CPU so much

>> No.64132174

>> No.64132176

>> No.64132191

As an layman my understanding is that this speculative processing thing is what made Intel processors so good, because they select data ahead of it actually being needed or something

This is what gives people access and so it needs to be shut off. That's the "patch".

Without this the processors need to wait to get an instruction before processing data (or however it works) meaning they now are less efficient and performance suffers. It's apparently workload-based, so PCs will barely notice it, but data centres and servers will be fucked as it fucks their performance at every single operation.

>> No.64132194

There are three bugs
>Spectre version 1:
Affects everyone but easily patchable (no perf loss)
>Spectre version 2:
Affects everyone, not patchable but hard to execute in a real world environment and can be mitigated heavily with patches

Intel only. Patches fuck perf hard in some usecases. Not relevent to AMD/ARM

>> No.64132201

>except Intel Itanium and Intel Atom before 2013
Price gonna rise up for these

Is Itanium affected? What about PowerPC? Sparc?

>> No.64132208

I don't see anything stopping the people trying to crack consoles from using this exploit if it works and gives them access to the console

Not at all. This could be used to trigger a war.

>> No.64132228

Don't listen to them. They are shilling against opensource (JavaScript most always presents us the ability to examine the code, since it is largely a client-side language).

nobody knows, because nobody cared enough to check

>> No.64132233


I read the google paper and they say that AMD is only vulnerable to one attack, and specifically: "If the kernel's BPF JIT is enabled (non-default configuration), it also works on the AMD PRO CPU."

So it's not even a ryzen cpu, and it looks like a simple fix in any case.

>> No.64132244
>> No.64132246

You must not be reading this thread (or thinking clearly for that matter). The big issue everyone has been talking about recently has been an issue specific to Intel CPUs. Intel, slinging mud, has exposed a flaw that every modern day processor has, including AMD and ARM processors.

Though the Intel specific problem sucks, this new flaw has the opportunity to btfo this entire planet.

and https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html

>> No.64132247

So as long as I don't visit websites, I'm safe, right?

Was it made after 1993?

If yes, then no

>> No.64132257

will this hurt my gayman fps??

So the CPU was predicting what data would be used and had it on standby for if/when it would be used, but this in and of itself is the vulnerability and now taking it away will cripple performance.

It was kinda like Intel Optane but instead of it being for your Disk Drive, its for your CPU

>> No.64132260

oh, i think i misunderstood your comment. yeah, if you could fiddle with memory, you could, theoretically, crack consoles without modchips.

>> No.64132261

Don't make statements without providing source or your opinion is immediately discarded.

Itanium no because no speculative execution. Same as pre 2013 atom.

>> No.64132281

Now you're just trying to make me happy

Hardware. We have empirically verified the vulnerability
of several Intel processors to Spectre attacks, including
Ivy Bridge, Haswell and Skylake based processors.
We have also verified the attack’s applicability
to AMD Ryzen CPUs

>> No.64132287

Yes, the spectre bug is much less serious short term since it's hard to pull off, but it can only be mitigated not fixed without hardware redesigns.

>> No.64132289
>> No.64132293

only by 30-65%, no biggie

S-shut it down!

>> No.64132309

>So the CPU was predicting what data would be used and had it on standby for if/when it would be used, but this in and of itself is the vulnerability and now taking it away will cripple performance.


Technically all it's doing is putting Intel back on a level playing field with everyone else. Problem is that we've grown accustomed to the superior world that Intel provided and going backwards will suck donkey dong

> However, for both ARM and AMD, the toy
example as described in Section 3 works reliably, indi-
cating that out-of-order execution generally occurs and
instructions past illegal memory accesses are also per-

The shill thinks we don't read sources. Ha, fuck off.

Is this on the hardware level or what?

googleprojectzero blogspot co uk/2018/01/reading-privileged-memory-with-side html

>> No.64132336

>> No.64132339

>> No.64132342

That is a picture from liberated Aleppo actually

>> No.64132353

>> No.64132373

>> No.64132377

>updating OS will patch out performance
>no benefit to me

>> No.64132381

>> No.64132384

Must have been severe for them to release it asap.

Ring 0. The same level that a malicious bit of code executed by your CPU (that you can't detect in any way) can overwrite your entire motherboard BIOS with all 0's if it wants and permanently brick your PC.

The problem is just Ring 0 access. It's the fact that a rogue Java script has the ability to drop a payload that can utilize the exploit. All from Ring level 3.

>except Intel Itanium and Intel Atom before 2013
Gonna stock up on those.
Seems like the libreboot thinkpads are dead.

>all modern processors capable of keeping many instructions in flight
Does it refer to OoO only ? Does it have a technical name ?

>> No.64132405

>> No.64132415

VIA decided to go for the security by obscurity approach I see.

except consoles run AMD apu's and Nvidia tegra based chips.

>> No.64132431

>Seems like the libreboot thinkpads are dead.
My T60 and X60s are likely going to be fucked up very badly by this.

I've also heard that this is some CIA psi-op that intel made to give them backdoor into people's hardware to around the OS.

>> No.64132442

>> No.64132448


>INTC INVESTOR ALERT: Law Offices of Howard G. Smith Commences Investigation on Behalf of Intel Corporation Investors


>> No.64132457


I only read the headline, chill out dickshitter

>> No.64132462

How do I protect myself against this exploit without this shitty patch? Would disabling JavaScript do it? Would most websites work without JavaScript?

I can't wait until the inevitable JS-based exploit that somehow fucks your whole kernel right up.

>> No.64132475

>> No.64132492

You can, patch.
or you can wish nothing happens.

Did you listen to the conference call? They lied straight to them and then refused to answer any of their questions or concerns

>> No.64132498

>> No.64132508

If privileges ever meant anything that shouldn't be possible. But due to this hardware level fuckery, who knows.

>a rogue Java script
Java is not a scripting language.

>> No.64132518

Completely isolating your computer. Have fun offline, and better not use external storage mediums either.

>> No.64132521

>> No.64132526

Block all ads, disable JS globally.

If the site needs JS, enable it for that time only (like to post a comment on 4chan), then disable it after.

And don't visit shady websites.

>> No.64132527

>> No.64132530

Good thing I just bought a itanium 9700 series based server in oktober.

>> No.64132540

>> No.64132545

Have you tested and made sure the exploit doesn't work?

Fuck it I'm running CommonSense™ 2017 and it hasn't let me down yet, I'll take my chances.

>> No.64132556
this looks bad and i'm worried

>> No.64132558

IIRC Itanium didn't even have out-of-order execution before Poulson.

>> No.64132569

The vast majority of websites do not require Java. In fact I don't even think Firefox supports Java out of the box anymore.

So all shIntel was doing this whole time was CHEATING their performance by intentionally using a security flaw as boost

really, REALLY makes me think

This couldn't be further from the truth. Why are you even on /g/? Holy shit what is happening to this board?

>> No.64132596

That's literally true.

Your PC hasn't had an easily exploitable flaw like this until now either. You don't even need to browse the wrong sites to get fucked by this.

>> No.64132614

>> No.64132626

Who the fuck is paying for fixing this mess?

Is SPARC affected ? Older ones use in-order but due being a barrel processor it keeps instructions decoded.

>> No.64132635

Literally as in the actual meaning of the word?

Obviously untrue. Project Zero executed variant 1 on an FX

>> No.64132645

i don't know but it better not be the government. i had a thought that trump has something to do with this because maybe obama used this backdoor to spy on him

>> No.64132655

Which is why I said block ads and disable JavaScript globally.

>> No.64132667



>> No.64132668

>> No.64132671

>> No.64132684

Then go back there. What you describe is called prefetching and something every high performance CPU does since like three decades. And Intel's CPUs still do it even with the patch. Performance would be fucking abysmal otherwise. What the patch does is separating the page table between user and kernel space, now you got two the CPU has to switch between. That causes the performance hit.

>Attacks using JavaScript.

>In addition to violating pro-cess isolation boundaries using native code, Spectre at-tacks can also be used to violate browser sandboxing, by mounting them via portable JavaScript code. We wrote a JavaScript program that successfully reads data from the address space of the browser process running it

>> No.64132711

>> No.64132716

>Your PC hasn't had an easily exploitable flaw like this until now either
But it literally has for the past 20 years

>> No.64132719


Wake me up

If this kills javascript what alternatives do we have

not an argument

Pray tell then, how else can people be infected?

>> No.64132759

>> No.64132763


>> No.64132771

>> No.64132794

Google, linux kernel devs from red hat, intel, amazon, students from multiple universities. Microsoft. Everyone.

>> No.64132796


Everything that connects your PC to other systems. Mainly mailing clients and external memory

>> No.64132811

>torrenting is now impossible without heavy CPU load
>encryption is now impossible without heavy CPU load


>> No.64132822

uMatrix or noScript.

>Mainly mailing clients and external memory

Not sure you mean by the last one, but I don't use a mailing client.

How do you know someone hasn't been exploiting it for years now without it becoming public knowledge?

Spectre cannot be fixed. Entirely new processor designs are needed.

>> No.64132847

>> No.64132852

Variant 1 is fixable.
It's 2 that affects all chips and can't be fixed.

You can be attacked by parsing CSS, not only running JS. You can't really escape.

I hope this won't count as boycotting an Israeli company.

>> No.64132866

That is a photoshoot that a journalist put together so he could try for one of those "award winning photo" awards

It's not genuine, the entire thing is staged

>> No.64132870

If you have to ask that, then I suggest you don't. You won't know how to fix broken websites once you disable it.

This is trumps fault

Works on my machine desu.

>> No.64132876

Lads I'm on a pirated Win7 SP2 that I never updated. Is there a way to just get the patch that Microsoft are releasing without having to install a load of updates? I wanna avoid those telemetry updates they added a while back.

>Date of Conference: 27-30 June 1995
>The CPU of the multi-chip module processor has a superscalar, speculative issue unit, and an out-of-order execution datapath.
Well fuck

Retroware fags were right again!

>> No.64132892

Unlikely but possible. We don't know, but if it happened it wasn't widespread

see >>64132816

>> No.64132904

At what CPU performance?

Why not?

>Next generation ILOVEYOU virus

>> No.64132914

my fucking sides, it probably does
>> No.64132917

This is true.

Time to break out those PA-RISC workstations out of the closet.

>> No.64132938

>> No.64132942

Didn't know there were such things for pictures that don't shit on the Syrian government

Burgers can't stop and won't stop funding Israel

intel dug so hard they found one amd cpu that amd themselves must've forgotten existed.

bulldozer mobile, bga socket

>> No.64132968

>> No.64132984

Maybe this is how China got ahold of the F-35 and other Lockheed Martin datasets without triggering alarms immediately.

>> No.64132998

I guess I have no choice but to update, then. In one fell swoop, my Nvidia card as been rendered useless.

I can't even comprehend this pain.

everything since out of order execution was added, because CPU does not check if the predicted memory area from branch prediction belongs to the process that invoked it. Hence, it allows to read that memory before flushing it.

>> No.64133040

>using password manager means nothing now

>> No.64133044
Looks like Itanium, Pentium Pro and Cyrix are also fucked.

>> No.64133063

Thank you for the clarification. Are there any benchmarks that have been conducted on meltdown patches for regular consumers? I knew I shouldn't have gone fucking intel this year.

Anons, time to make /g/pus. Let's set this shit up. Let's take back the free world.

Did HAL get it right, though?

I don't see how Intel is gonna survive this desu, they are really fucked

>> No.64133091

Let's make the logo!

Let's face it, if there will ever be a crowd sourced CPU it will be made by /a/ because its required to get that bootleg Chinese cartoon sharing symposium back up. /g/ is not only to incompetent but also has no reason to do so.

>> No.64133139


>> No.64133165

That's a screenshot from wikipedia.

>> No.64133205

At this point just burn everyrhing and start rebuilding.

literally /ourguys/

>> No.64133248


It's out
>mfw it'll be tommorow before benchmarks are out

>> No.64133267

>uses speculative execution

Temple OS runs everything is ring 0 so everything can read and manipulate all the memory anyways. God told Terry this would happen!

>> No.64133316

>> No.64133342

I don't care about this cyber"security" bullshit. I have Kensington locks, it doesn't matter to me.

that's incorrect, what they fx pro is bristol ridge (replying to myself)

Ok memes have gone too far

Please tell me the Z80 is safe.

It’s not

Sometimes you get something even better this way

but i don't want to take an fps hit in my gayman :(

How long does it normally take it to actually show up in Windows Update?

The security update is set to automatically roll out to all Windows 10 desktops today at 5 PM ET, though we’re not seeing it on any of our systems just yet. It’s also set to become available on other Windows 7 and Windows 8 systems, though it will not appear automatically on these systems until Tuesday, January 16.

>> No.64133642

>> No.64133658


>> No.64133677

>> No.64133716

If you "just" got it, maybe you can still return it

>> No.64133853

>> No.64133854

>> No.64133882

During the CIA leaks, it was found the CIA had found vulnerabilities in AES256 and hadn't bothered to tell anyone about it.

just buy a key from pajeet for 2 dollars, still been using mine since forever.

>> No.64133897

Pirated as in you use some edited iso downloaded from torrent or clean windows iso with daz loader?

Well, it's been three hours and I don't have it. I assume the "roll out" is gradual then. Hopefully it's here in the morning so I can get to benchmarking.

>> No.64133917

I installed The Crew when it was free on Uplay and that malware updated my win7 and made it non genuine again so try that.

>I assume the "roll out" is gradual then

No one is too much of a poorfag for this

>> No.64133973

Also, forgot to ask, anyone know a formula for excel that'll print out the inverse of what I put in? i.e. 10 to 9 outputs 10%

>> No.64134035

I'm not even joking. The pc restarted during installation and some kb(bunch of nunbers) thing was downloading and installing.

>> No.64134074

Clean iso with some sort of activator I think
>> No.64134100

>Speculative execution explicitly program controlled
Does this mean we can turn it off ?

