File: 106 KB, 250x250, 1511219276071.gif
Retard here.
What's the quick rundown on the Intel shit.

It affects everyone, including AMD.

All intel cpu even pentium 2 is fuked

Making Damage control saying all arm/amd is affected

no it doesn't.

Ok but what do you mean by fucked

Bogdanoffs answer to the
Wait, what was the question?

the biggest impact is going to be in datacenters since the data flaws affect server CPUs as well. We can expect loss in market share where Intel gets most of its business.

hm... we might have a bot.

wrong. its intel only

meltdown, which is the really scary vulnerability, affects the last 20 years of intel products

amd is not affected by meltdown

Two bugs. Both make it possible for a program to read protected information that it shouldn't have access to.

Everyone's up in a craze about the more dangerous one, Meltdown, and patches are rolling out currently for it. Reports are saying that there are performance losses for Intel processors, due to the how the patch works.

The degree of performance loss depends on your workload, but the numbers being thrown around so far suggest anywhere from 'negligible' loss all the way up to 30% performance drops for Intel chips.

It's also very widespread, too, and affects essentially everything all the way back to the original Pentium.

There is a second bug which is harder to make use of, called Spectre. It affects both Intel and AMD, as well as other makes. Unsure about this one yet, since everyone's focused on Meltdown.

Does it mean a literal meltdown? Burning out the chipset? Or is it a fancy name

Yes, it heats up your processor until it melts.

Fancy name.

File: 275 KB, 1297x846, file.png


it's referring to Intel's stock value when the full implications of their incompetence goes public after all the datacenters in the world become 60% slower in the blink of an eye

Saw this earlier, but good to post nonetheless. This is why I'm not too worried about the performance losses. I'm waiting for the update to hit my system so I can do some testing for myself and see.

>everything is about gayms and shitty file compression
basement menchildren get out!

File: 94 KB, 814x803


disable javascript

>Video games

Very useful to see if your daily use will be affected by Metldown.

Use some common sense. For 90% of the people here, that's all they care about.

in a nutshell
>it's fucking nothing

There are two vulnerabilities: Meltdown and Spectre
AMD is affected by Spectre (the harder to exploit of the two)
Intel is affected by both

morons don't know what caching is and got buttmad

What do you do with your home personal computer? Genuinely curious.

is this what a happening looks like on /g/? because it's pretty damn amazing

File: 6 KB, 275x183, BRAIN THINKING.jpg

is it menchildren, manchildren, menchild, menchilds, or manchilds?

File: 32 KB, 617x1054, phoronix_intel.png


Spectre 1 has been fixed, Spectre 2 has not yet been proven to work on AMD hardware.


maybe being a paid shill.
Anyhow, those "benchmarks" are misleading at best, the problem for Intel isn't some manchildren will get less FPS, it's the server and datacenter that matters.
If /v/ doesn't realize computing exist beyond call of duty it's their problem.

No but in theory the exploit can be used to brick your motherboard.

I use my personal computer to program, compile other software, render videos (from that time your girlfriend went out for girl's night), and trade stocks.

Compiling software just got 30% slower, video rendering is fucked, and I can't trade stock because my bank is 'under heavy load' -- all of these are Intel's fault.

While technically correct, this is /g/; nobody shitposting on here has any reason to care about that. What matters to them is what is going to happen to *them* specifically, and that is what we're starting to figure out now.

Show me some vc for your projects.
Your editing portfolio?
What terminal software?

I highly doubt you can. You sit and shitpost on /g/ all day, that's what you do.

Show one example of AMD having Spectre v2 on it, i'm fucking waiting

>(from that time your girlfriend went out for girl's night)
Why'd you have to add such cringy shit into your post? I forget how young the posters are here sometimes.

File: 43 KB, 256x256, Confused High King with Interrogation Marks.png

I've pretty much got downs.

How does this effect me, as someone who just browses a select few websites and plays some vido gams?

As long as I'm not retarded and download coolmusic.mp3.exe, will anything change for me?

Yes I have intel. I'm on W7 and I have automatic updates off

Rogue JavaScript can read your full memory, find right place to Inject data and you are fucked

>> No.64136561

I'm reading what you're typing right now.

File: 7 KB, 267x323

>having js enabled in the first place

File: 15 KB, 353x251

Who could be behind this post?

File: 18 KB, 261x181

ty for this

File: 90 KB, 633x746, file_5.png

Not gayman here for the assmad

my computers are both old I have q6600 and fx6350 am fucked? do I need to download anything to fix it?

>first reply again
Pretty funny shill

Exploitable through Javascript which means it would be very easy for someone to hack your stuff if you don't update

It's too late, kiddo, you've already been hacked ;)

You are as valuable has you have always been exploits are every where. You just know about this one. You will be fine.

inb4 this was an NSA exploit and just now someone found it. Just like juniper finding their backdoor.

I don't know about Windows but it seems the more syscalls you have the more you're hurt.
You might also find lots of performance degradation for the kernel itself.

So for most applications this will barely matter. I've always perceived code that does lots of syscalls as inherently uninterested in performance. Kernels having to isolate their own memory I could only speculate on.

Overall this looks very bad for Intel though, that's probably a much bigger factor than the actual performance impact. It destroys trust in them as a secure platform for people who really care about this. How old this is is especially bad.
With how virtual machines for servers is pretty much the only way we do server hosting now it's pretty major on that front. Performance there matters a lot for the companies hosting the VMs. You'll probably not see any difference as a customer though.

>I'm on W7 and I have automatic updates off
You face greater threats already.

File: 26 KB, 600x610

File: 1.63 MB, 1415x2326, 2018-01-03-15-18-07.png


Only the simplest patchable Spectre attack affects AMD, the other two do not.

It's not the exploits you know about you should be worried about. Exploits have always been around.

File: 173 KB, 396x385

>mfw I don't care

Building a server machine what kind of flashy shit should I put in it ?

No it's a big thing. Just not for gaymers.
Regardless you should be considering Ryzen as your next purchase. Just read Agners Ryzen tests and his manual. It's pretty clear cut.

File: 63 KB, 499x523

Nah my nigga that shit is too weak I am thinking Quantum processors for cpu and vga
I mean't flashy lights n maybe like a smoke machine and strobe lights or some shit.

File: 65 KB, 744x687

though I could certainly make use of them.
what would be comparable ? ?

File: 298 KB, 654x639

sorry to hijack the thread op.

>I'm on W7 and I have automatic updates off
the absolute state of gamer retards

File: 61 KB, 1000x800

as my gift to you

Pajeet please. This is not effectively achieving your goals.

None of those is IO intensive. Post IO benchmarks

All three attacks rely on a side channel element. AMD is immune to meltdown because privileged memory addresses immediately rejected before entering the execution stage at all. Spectre v1 uses a similar OOE/line cache attack which simply searches for kernel pages by repeatedly injecting eBPF bytecode which runs speculatively during a misprediction until cached kernel memory is detected and then can be completely dumped. Spectre v2 demonstrates that an attack can be executed from a guest kernel on the HOST kernel by recovering branch predictor history buffers within a root run hypervisor allowing hypercalls (e.g. KVM acceleration, Xen).

For sure meltdown is the easiest to access because it is possible from Ring 3 directly and not from guessing addresses thrown from kernel context bytecode interpreters or root privileged VMs. The other two do present alarming problems with the aggressive and potentially unsafe way all processors are designed.

English, doc.

File: 11 KB, 478x97, amd.jpg

Linux kernel patch

lmao just sort your shit to not cache miss

Has nothing to do with this you fucking moron.

>which runs speculatively during a misprediction

File: 1.34 MB, 1294x1222, milkwalker.png

>be a company
>release first desirable product in years in a market that you have been clawing away at after decades of shrewd business practices by your competitor
>its revealed your competitor's product is dangerous and broken
>its revealed your competitor's product has 3 major faults that the only known fixes are to make them preform worse
>competitor issues statement it is working with other companies to fix the products they and YOU made
>issue a statement that your products are not dangerous and broken in these ways
>vendors don't care and nerf everything anyway
>your competitor gets off scott-free using FUD
epic timeline.

They can't do that, it goes against the narrative.

>these bugs coming to light now
Is there any evidence anyone's exploited them?

File: 19 KB, 300x300, jackie-chan.jpg

>root run hypervisor

javascript control is better


File: 54 KB, 679x758


>> No.64138583

What's the name of the fucking update for Win10?

File: 65 KB, 679x711


>> No.64138620

Should I stay away from browsing manga websites for now

File: 283 KB, 1024x1099


File: 248 KB, 680x486, hiroshimanagasaki.png

Thanks for the spoon feed, I only wish I was lurking /g/ like I usually do when this broke.

computers are 100% obsolete now
buy an abacus

>> No.64138717

doesn't the nsa have a treasure trove of zero days they're just sitting on?

What's the name of the fucking update for Win10?
>What's the name of the fucking update for Win10?
What's the name of the fucking update for Win10?
>What's the name of the fucking update for Win10?
What's the name of the fucking update for Win10?
>What's the name of the fucking update for Win10?

Spectre is INCREDIBLY hard to implement. It's based on artifacts left behind by the type of branch optimization and speculative execution that modern chip architecture uses, allowing people to guess the timing of memory references. You can use this to guess the functions that the underlying code uses, and in turn guess the data that is being returned.

THAT'S SO HARD TO DO, especially when you're operating on a non familiar system.

That's why people aren't exactly freaking out about Spectre.

>> No.64138791

You shouldnt go to them in the first place, lame weeaboo.

So, it's nothing. Just install the patches.

And for Windows 7?

What about older architectures?

This. People freaking out about javascript implementations forget that you have the V8 engine introducing latencies of it's own. It's like they never worked with the language before

Fucking upgrade to Windows 10.

Basically Meltdown allows for privileged memory to be exposed by loading kernel memory references into CPU registers and executes an incoming instruction that loads probed data into cache. The reason the CPU does this without causing the program the crash as would be in normal cases is because instructions don't necessarily execute sequentially on modern processors; by executing certain instructions ahead in a conditional which is believed to be more likely executed, there is potential speedup.
Spectre also exploits this by loading out-of-bound addresses from kernel context or loading foreign data pointers into the branch target buffer (a buffer containing what the CPU believes is the next set of instructions to execute next) in a root run VM.

Misprediction does NOT arise from a cache miss. A cache miss will halt the instruction to wait for the MMU to feed it data. Branch misprediction AND BTP (target prediction) explicitly predetermine conditional execution by feeding the target address next into the pipeline - a misprediction would mean that the pipeline is cleared and the new branch must be fed in. The exploits rely on loading the payload into cache (in Meltdown and Spectre v1) because the speculated branch has preloaded the following instruction into cache and executed - however, in Spectre, additionally, it is possible to measure the amount of time the speculative branch takes as the saturated cache line loads an out of bounds memory offset to rebuild the memory map and determine the address of the kernel. With this OOB bypass, you can then dump kernel memory.

Yes, those programs are not syscall heavy and so the performance should remain roughly the same.

With a large number of instructions you can still discern with the Chrome performance timer the behavior of the CPU with the use of shared array buffers. Google will be updating Chrome to mitigate this at the cost of SAB and a performance cost.

File: 100 KB, 288x288, death is certain.jpg

>What's the quick rundown on the Intel shit.

you stupid faggot, you should be downloading them instead of reading them off a site
mangatraders still exist

>> No.64139078

>recommending moving to a malicious operating system to fight a malicious exploit

>> No.64139163

But measuring the memory reference timings is so so so ambiguous. Building a memory map by timing the returns appears to me to be an almost impossible task in an unfamiliar system. Similarly, I understand that using POSIX safe functions is good form when writing for portability, but it always struck me as overkill.

>> No.64139223

How would this affect me, personally? If I do not update and just ignore all of this and so avoiding the performance hit, what kind of danger, exactly, would I be in and how?

Dumb normalfag.

File: 150 KB, 198x328

In the 1.5 days or so I've gone unpatched can my computer still be considered safe or it might as well be physically in the hands of criminals? I've been doing basically nothing but watching Hidamari Sketch and playing Blazblue those past few days.

>> No.64139420

What are the effects and what programs can read what data?

File: 1.60 MB, 200x151, shits on fire yo.gif

All your system credentials and keys stolen and complete pwnage of your machine, all from a small slice of javascript on a webpage.

>>64138143 here
I see. Thank you. I've been reading the paper and your explanation is really good. Now I understand why they mentioned buffer overflows. The issue is that the speculated branch has access into kernel memory, correct?

Optimization is truly the root of all evil.

>> No.64139433

javascript malware can now bypass all security on your OS and basically gain administrator rights to do whatever the fuck it wants.

you may potentially be safe when firefox/chrome updates their browsers, but you'll still be wide open to untrusted executables.

basically means all anti virus/os protections are useless at the moment.

>> No.64139450

won't the microsoft patch fix this vulnerability though?

File: 906 KB, 500x282

>windows, mac, linux
>os, device, kernel

yes it would be much easier to understand if they listed NT, XNU, Linux

>> No.64139788

The fix needs to be specific to the motherboard manufacturer, right? I have an itx board that doesnt appear to have been addressed yet.

File: 81 KB, 244x274, Intel glue fanboy.png

Except it doesn't affect AMD.

>> No.64139842

>javascript malware can now bypass all security on your OS
we Runescape botnet now

>> No.64139846

except it does

>> No.64139926

Since nobody actually cared to read the academic papers and, those who did and post here, clearly lack and academic background to understand them, here's a quick rundown.

incorrect and badly formatted.
>Spectre 1 has been fixed
>Spectre 2 has not yet been proven to work on AMD hardware.
Almost correct.

>> No.64139929

Nope. But if you want to get semantic, only v1 on certain older CPUs.

>> No.64139952

>> No.64139975

>all this "proof"

Not an anon thats posted on this thread but the academic papers you speak of, is it related to the 2016 blackhat report that's been floating around?

What is KB for windows and can it be downloaded and installed individually?

>> No.64140024

>javascript malware can now bypass all security on your OS
Post proof. It's a third day but nobody can provide any proof on this. The shit is made up.

>> No.64140037

>> No.64140077

You are all fucking assholes shilling AMD instead of helping our fellow faggot

It's basically a 5% (Some say 50 or 25%, but the 5% was confirmed by an intel employee) performance hit on everything with intel in it because there's a design flaw which theoretically allows anything to bypass the kernel and talk directly with the hardware. Since it's hardware based, the fix can only be applied using software. Software fix makes I/O slower but more secure. Servers and data centers will be the most affected as their only job is I/O.

Of course, the fix - not the bug - will affect everything, including AMD. If you have an Intel CPU then if you don't get the fix anything including shitty javascript can skip the kernel and run as an administrator.

File: 897 KB, 800x430

>can’t lose productivity if it’s a Core 2 Duo

Meltdown are Intel exclusive

5% eh
https://twitter.com/grsecurity/status/948170302286172160 more like 65

I don't know anything about the PC stuff but this does not look good...

So for Intel to fix this they have to make a new cpu layout right?

The last time they tried that it did not go so well.

please respond I still don't know what to do. I don't want to get computer aids.

also the computer with the intel cpu is still on xp. it's an old pc I kept around for compatibility with older games and stuff. since there's probably not going to be a fix for it can I just never go on the internet with it and be safe?

just say it doesn't affect Ryzen so they can't worm their way out of it

yes you're fucked, what part of ALL INTEL SHITS SINCE 1995 IS AFFECTED do you not understand?

if that old XP pc is just for old gaymen, then you can limit what you do on it internet-wise, eg don't be logging on to critical shit from that pc....maybe that would work?

More accurately, Spectre 1 is scheduled to be fixed by AMD, so this will make AMD invulnerable to all three provided no one can come up with SP2/Variant 2 on AMD hardware.

I wonder how all the advertised encryption for Zen CPUs has worked out, does Spectre return garbage data because of said enryption?

>Of course, the fix - not the bug - will affect everything, including AMD
Not anymore because Linus declined jew bribes
Well it still may affect amd to some degree because the fix was made in a hurry and probably not all the changes are configurable, but it won't be as dramatic as intel wanted it to be for amd.

So for us retarded non-enterprise faggots, what kind of shit's going to see the biggest hits out of this and what won't? Is any generally heavy CPU shit like video encode/decode fucked? Or is the worst shit just going to be database shit and stuff?

File: 53 KB, 563x268, DSpf9XAX4AAikB4.jpg

>complains about shills
>literally parroting shill propaganda
there are 2 different sets of bugs, only one of them requires a solution that causes a 30-60% slowdown, and that one strictly affects Intel and they can't fix it via firmware update.

AMD is affected by a different bug that doesn't have the large performance penalty solution, and it can be patched via firmware update anyway.

you can scream and shout "IT AFFECTS BOTH" all you want, but it's completely misleading.

File: 105 KB, 820x602

another retard here who fell for the Enterprise 2016 ltsb meme
will we get an update too? when?

Spectre 1 only happen on FX pro and apu, it using custom bios setting.

Well they will definitely address the issue in the new stepping, for sure. But it was already fixed in software anyway. Same thing as linux segfaults on ryzen, it was indeed hardware bug of early batches but was patched in kernel anyway.

Just disable the JS in your browser. Use Noscript/Umatrix (google on how to disable js by default with it) and you'll be fine as long as the admins of the websites you visit and enable js for aren't dicks enough to insert malicious code (wouldn't trust Hiro on that though).

absolutely nothing u gaymer


>> No.64140524












>> No.64140542

The meme you fell for was intel, senpai.

can you tell me if running a fresh install of 17.10 ubuntu is safe enough on a computer with intel cpu? should i enable the tick box for intel microcode in additional drivers setting?

besides enabling ufw is there anything else i need to do? do i need a bleeding edge kernel? like enable the 'proposed' package tree?

Why should I
I run Ryzen

>> No.64140567

>can you tell me if running a fresh install of 17.10 ubuntu is safe enough
go and get openpepe
I mean opensuse
that or clover os

now is not the time for epeen comparing and distro wars

i just want to know how to avoid getting pwned not get memed with a meme distro

actually now is absolutely the time for choosing a distro that doesn't have systemdicks
make a live USB and test out an OS right fucking now, it's as easy as choosing the USB stick with the OS on it from the bootloader

is just not using a web browser or downloading anything enough or do I need to do something in network configuration to prevent it from connecting to the internet? I would just unplug it, but I want to be able to transfer stuff to my other computer.

so what do I have to do to fix shit on my computer with the amd?

Well they haven't released a patched kernel for 16.04 LTS so I can't imagine they'd done so for 17.10

What do I do tho?

you shouldn't be on FX anymore when Ryzen stomps on it

Install TempleOS


>> No.64140736

I can't upgrade because it's a new socket and I'm too poor to replace everything. also fuck windows 10.

okay well what about the intel microcode driver? should i enable that or disable?

Where did this bug come from? Was it here all along? If so why didn't anyone know about it since apparently it effects every CPU since 1995.

Find the patch then, Microsoft still rolls out XP patches, but here's the catch: it's for fucking businesses only.
>also fuck windows 10.
You can install windows xp on Ryzen, actually, but it's an absolute pain to get working because of missing drivers. Windows 7 is easier to install because AMD has the chipset support surprisingly enough.

File: 193 KB, 336x400


>> No.64140941

>> No.64140964

>Was it here all along?
>apparently it effects every CPU
>why didn't anyone know about it
Nobody expected intel to be this bad

What do I do with windows 7?

No, upgrading to cancer Win8-10 is not an option. Where's my security patch then?

have fun

>both Firefox and Chrome already have fixes for browser vulnerabilities
>not running them together with noscript

bro 1710 sucks ass
1604 works fine
but try both with the live cd first
also use lubuntu and apt-get tlp
we still don't know it will affect us

you can easily use wine for old gayms with dx9

>actually now is absolutely the time for choosing a distro that doesn't have systemdicks
how so?

on some tracker or elsewhere ''stolen'' from paid shmuks i mean customers

guess it's time to utilize the free w10 upgrade you get for claiming to be handicapped

So do you have to download some malware or visit a bad site to become victim to this? Of course I'm going to update, but just wondering if I need to go changing passwords and shit afterwards.

>ARM not affected.
I guess the """dumb""" phone posters win again :^)

Spectre affects everyone (Intel, AMD and ARM)
Meltdown only affects intel

Last time i turned on automatic updates on my win7(pirated) it fucked my pc and kept hanging on shutdown forever, rolling back fixed. So what are the odds i grab this update exclusively from microsoft site and makes my pc release mustard gas?

Man you guys are like babys. Disable java and flash plugins run an ad blocker use common sense.

>how so?
So that you don't get an "I told you so" a second time when systemdicks blows up. It's the next bomb in the making. Nothing good comes from centralizing your shit like that. It becomes a monster that devours everything.

>> No.64141215

>> No.64141227

Selective updates, you nigger, you can fucking download standalone packages. The windows 7 patch is already available as a standalone.
I bet you didn't turn off updates from services but from the control panel and thought you turned off the service when actually it was ready to run at any time.

This drama sure has died down huh. It's like the world is not ending. Even the news fell asleep using worse case scenarios and hyperbolic headlines for clicks.

>systemd vulnerability found
>it gets patched

Are you seriously trying to compare a hardware design fault with a potential bug in an open source software?

say goodbye to your twitter account

File: 22 KB, 699x516

i have no idea what any of that means but fuck it sounds pretty bad there chief

>> No.64141668

>> No.64141689

>> No.64141706

So from what I've read this will influence IOPS/ I/O stuff with NVMEs mostly so industrial workloads in datacenters and servers?

Given that no end-users with desktops are affected, could someone post a benchmark results for a Linux distro of their choice? That is where the supposed 30% performance hit is going to happen after installing the patch.

Given that no end-users with desktops are affected, could someone post benchmark results for a Linux distro of their choice? That is where the supposed 30% performance hit is going to happen after installing the patch.

>> No.64141724

i never used the browser's "save password" gimmick nor use a password manager
the only thing i have is a paper with all my shit
in the data theft front i'm not that fucked, right?

you're actually pretty secure
even the Russians went the paper route a while back

If you type in a password and someone installs a keylogger, it won't matter if you didn't save it.

you know, these password CIA niggers are relentless.
If they can't read the passwords, they will just break into your home and steal your piece of paper

>> No.64141794

>deal supposedly ended dec 31 2017
>still works
thanks, microsoft

but a keylogger is typically easy to detect by any anti malware program, is it not?

jokes on them, i wrote it all in lemon juice (joking ofc)

>> No.64141984

the problem is that it doesn't need a keylogger program you download and execute, just a simple javascript drive by

>> No.64142018

>> No.64142048

>> No.64142054

>> No.64142086

Meltdown is like you're at a restaurant and you order a hamburger and eat it. Then you give the hamburger back, but you still remember the taste of the hamburger and you walk out without paying.
Using the memories of the taste you can then figure out where the meat for the burger came from

>> No.64142087

>So what's spectere doing?
enabling it

File: 48 KB, 800x729


>> No.64142138

Can we rename meltdown to "memories of beef"

>> No.64142152

How long should it take for intel to make cpus without this security breach?

>> No.64142156

>memories of beef
man, this is a cool name for an exploit

>> No.64142193

fucking years, 5 years minimum
they have to go back to basics on this, right back to the drawing board
whatever new architecture they have will be fucked if it's still based on the ghost of pentium pro

>> No.64142210

>> No.64142225

>Will we go on anarchy because the Wall St. computers will be hacked
Nope, they run on gnu/linux. They'll have the patch. http://www.computerworld.com/article/2510334/financial-it/how-linux-mastered-wall-street.html

>> No.64142256

>the quick rundown on the Intel shit
>> No.64142264

mind my nagging, but how would that actually work?
i'm not exactly tech literate, but is javascript THAT cucked? i get the kernel stuff, but a driveby keylogger?

>> No.64142276

yes, it's that cucked

>> No.64142290

AMD fanboys sure are desperate.

>> No.64142292
File: 24 KB, 112x112

I'm also a retard and understand nothing.
So what can I do to be safe? Am I safe? Do I swap out my intel CPU for an AMD?
I use LastPass and lots of cloud programs to store miscellaneous stuff for convenience. You could say my entire life is online somewhere.

Am I fucked? Should I off myself right now?
I just want to play video games.

>> No.64142317

>> No.64142336

Make sure you are running latest security updates no matter the OS you are running.

If you have too old OS for security updates, you need to update or else you will be danger to yourself and others.

>> No.64142344

>> No.64142350

if your PC is connected to TCP/IP you are vulnerable, this applies to every breach, but this is a very very nasty breach since it is at kernel level.

Enjoy bitcoin mining if you don't get security updates.

Oh and one of the sec-risks also influences phones.

>> No.64142354
File: 515 KB, 551x713

>muh Coffee Lake
Enjoyed the wait, Intelfags?

>> No.64142368

>10-15 years.

>> No.64142392

>Intel stock only down by 3%
lmao. there is no hope.

File: 44 KB, 1214x306, 3t.jpg

what do

>> No.64142416
File: 46 KB, 714x270, 3r2q3.jpg

what do

Love playing games at a high frame rate. AMD fanboys will never experience this.

>> No.64142432

>ME issue.
Now now anon, that is a THIRD (second Intel) dangerous vulnerability for Intel CPUs, which is a different thing, but you should totally fucking patch it.

0. INTEL ME issue (Intel only)
1. Meltdown (Intel "only")
2. Spectre (intel+amd+arm)

and Shintel stock is only down 3% after this crap lomfao

I told you idiots like you don't understand the stock market.

>> No.64142510

Then here, since my mobo is MSI
And it would appear whatever fix I'm supposed to get isn't compatible with my low end board

You might not have ME in your CPU my dude. Like it's disabled.

patch for windows 7 when?

File: 19 KB, 296x107, 1111.jpg

Yeah looks like I don't have it

Not having ME is a fucking good thing. Rejoice, faggot, not all is broken in your life.

There must be an nsa bill being pushed through the senate

I'm getting mixed messages here, do I or do I not install this ME driver thing

I'm not sure I can even install it, the only thing I find for it in Intel's website says it's for Intel NUC

You don't need it. You're getting a false equivalent message from Intel's program, like that Equifax bullshit program that asked to get your shit fixed even when nothing was wrong and you're not on Equifax.

>> No.64142740

Well then I guess I'll just get the newest windows updates and see how this ends

God damn I was happier not knowing about this

File: 22 KB, 260x260

>tfw furiously masturbating to 8008 on my abacus when I shake it too hard and it goes to 7965

>> No.64142776

My dude. There's three things going on if you have Intel CPU. ME has a terrible exploit (what you worried), Kernel has terrible exploit (Spectre & Meltdown). ME is fixed by Intel drivers if you have ME, second one (M&S) will be fixed by OS updates granted you get OS updates.

File: 38 KB, 400x232, greysq_lat.gif





>> No.64142828

It affects on AMD 2, bro

>> No.64142834
Actually I just found this

Does this mean I'm safe from the ME issue since my CPU is 4th gen?

Well if you don't have ME you really can't be exploited through it can you?

Yeah I guess

sorry anon I'm tech retarded

Yes, totally made up. Microsoft is desperate trying to push the patch so it's probably nothing serious, right?

>> No.64142992

ok, so what do we call spectre?
I don't actually understand how that one works.

>> No.64143007

>was confirmed by an intel employee
Totally trustful source then.

>vendors don't care and nerf everything anyway

Do we have a source on this? Last I heard, the W10 fix only applies to Intel CPUs

>mangatraders still exist
That's a lie and you know it. The new MT is completely different and has barely anything on it.

It exists
As a giant archive in the torrents that no amerifat can touch because of filesize

Everyone's wrong

Reminder that these people are not your allies, thanks Bobama

>> No.64143198

>> No.64143276

And sites run by a certain nip that randomly injects steange code into them

>> No.64143279

why am I so aroused when seeing this image?

>visit shady russian porn sites loaded with malicious ads and scripts
this chinese board already has shady code appended by hirohito

>> No.64143383

>Buy ryzen you dumb nigger
Cute. Especially when you attempt doing that in a third world country.

But a solid defense against that was created in a matter of hours the very day it was discovered

>> No.64143497

intel shills, i so fucking hate you right now, pls kys and gtfo my boards reeeeeeeeeeeeeeeeeeeeeeeee

>> No.64143534

Where is the patch for windows 8?

>> No.64143565

>> No.64143751

>> No.64143765

Its literally fucking nothing, /g/ are just sperging out because they're amd fans



>> No.64143842

>> No.64143890

>the 5% was confirmed by an intel employee
sounds trustworthy

i don't understand how this is a problem for clients
JS is still sandboxed inside the browser so worst case scenario it might get a password or two until the sandbox is emptied?

I mean intel

>> No.64143946

you mean console fags?

is os related and patched
nice try

Meltdown let you access any memory in system. Sandboxing do nothing against it. It completely bypasses any software defence before OS patch.

>> No.64143996

>>it might get a password or two
>thinking this is remotely acceptable

>> No.64144037

>your gaymes are mostly unaffected
>please ignore the absolute clusterfuck this is creating by the need to get an updated kernel running on every Intel based system of the last decade
>> No.64144038

it lets you READ kernel memory, right?
obviously it's not but the chances of encountering JS that knows exactly where to look for the password that you might or might not enter is low isn't it? i guess you could make a JS keylogger that works as long as the script is allowed to run?

just not understanding how this is being made out to be worse for clients than the NSA backdoors leaked awhile ago. obviously on servers this is terrible.

When code is run it is passed to the cpu, due to the nature of meltdown cpu is compromised so when the code is run it can instruct cpu to read code anywhere in memory (outside sandbox)

>> No.64144059

>> No.64144075

You got CIA niggered and so did the rest of the world for over 20 years

>> No.64144079

>read kernel memory
>you now have root rights and can change it
Sure, not an issue at all

so this does allow you to write to kernel memory? i thought it only allowed you to read it...?

>> No.64144113

It also lets you read memory from other processes, for example programs such as keypass and lastpass.

>obviously it's not but the chances of encountering JS that knows exactly where to look for the password that you might or might not enter is low isn't it?
Many people use keypass/lastpass or some sort of system password manager (for example keychain on macOS). It's pretty trivial to make code that targets these specific systems, and there are plenty of people who use them.

>> No.64144122

If you can read kernel memory you can get root access. After that you can do whatever you want

>> No.64144184

>> No.64144197

ipad pro unaffected. What's a computer?

>> No.64144206

>> No.64144218

so ironically password manager users are more affected by this than retards that use 2-3 passwords everywhere. thanks for clearing that up.

>> No.64144231

>> No.64144254

Well, in this particular case, yeah. Kernel patch fixes that though.

It can also be used to hijack active sessions though, so it's not merely about passwords.

>> No.64144256

Passwords don't work to well if you can just read them. Their position in memory is randomized, not in the pagetable. And that is what meltdown gives you access to.

>> No.64144281

It's a feature it's real mode for modern CPU intel designed it on purpose and AMD stole it. Use only authentic intel inside (TM).

>> No.64144335

regardless, it's not going to let JS get root access, right? so it's bad, but not nearly as bad as EternalBlue or DoublePulsar were.

>> No.64144345

Not with KPTI enabled

>> No.64144359

How could that in theory happen? Wouldn't you first have to visit an untrusted, malicious website and disable your script blocker for JS to be able to execute anything?

>> No.64144516

>> No.64144581

>kernel and run as an administrator.
Like the administrator in user list?

the 86 is old the 88 is the latest

>> No.64144665

>> No.64144667

without the patch JS can cryptolock/get ACE outside the browser by using this?

>> No.64144668
File: 60 KB, 693x663

nice meme source you got here

>> No.64144689
File: 63 KB, 313x230

So basically this only matters for data centers. For consumers it hardly changes anything and doesn't make any CPU surpass or fall behind another one.

>> No.64144692

Yeah, my Ryzen manages to get only 150fps compared to 155 on the 7700K.
It makes me wake up and cry at night.

>> No.64144725

Not just JS but any code that is executed

>> No.64144744

so spectre is just a minor concern?

Chance that windows themselves developed it to kill off windows 7 holdouts?

>> No.64144748

Because this is /g/ and not /v/ and fucking up x86 server infrastructure is a topic of interest here

>> No.64144774

>> No.64144775

>> No.64144778

>> No.64144787

>> No.64144812

>> No.64144859

If you can find the location of the password in question in the kernel side pagetabe, sure. Which shouldn't be to hard since all software security features to prevent that from happenig are useless.

>> No.64144881

>> No.64144884
File: 141 KB, 405x490

>autism, the post

Nope, but it can use timed cache attacks to fuck you.

>> No.64144931
File: 187 KB, 568x612, DSpf9XAX4AAikB4.jpg

>5% was confirmed by an intel employee
>will affect everything, including AMD

>timed cache attacks
aren't those used to get keys? why would you need to do that if you can just lookup the root password?

>> No.64144983

>> No.64144993

>people still trying to pin it on Intel when it is a concept common to modern processors that gave them such speed-ups we take for granted today
Put all your money on graphene boyos, it's gonna moon soon. Silicon has been shit on yet again.

That's JS. It'd need to do that initial step to get to the level of finding passwords.
It needs to jump out the browser sandbox first.

>> No.64145011

hey looki. i have a self affirming and validating benchie too.

>> No.64145096

Fuck are you on about?
I despise Intel.
It still affects everyone, cunt.

>> No.64145104
File: 127 KB, 657x527, apustaja.gif

>It needs to jump out the browser sandbox first.
So I guess what I'm not understanding is what the step(s) is/are in between finding the root password and getting outside the browser sandbox to do whatever you want.

Sorry for stupid.

>> No.64145158

Use meltdown to get access to the kernel space side of the page table. Find password in page table. Now you're free.

>> No.64145201

So, let me get this straight, what you are saying is AMD processors are inferior because they don't have these massive increases gained by such pipelining?

>> No.64145216

>> No.64145250

oh my a circular reference. nice. and so quick

lole stay slow, nerd

>> No.64145292

No. They do speculative execution too. They just give you a page fault if a ring 3 application is trying to stick its nose into the kernel space side of the page table.

>> No.64145341
>Now you're free.
i still don't get it desu
somebody said earlier javascript can't just open up a shell and i don't know enough about it to know how getting the root password allows it break out
>use meltdown to get root password
>now you're free

>> No.64145369

>calls me a nerd. on /g/
s-should I be be feeling this warm sensation in my chest... i-is it happiness? waaah~ i'm so proud of myself. Thank you for the confidence boost senpai.

>> No.64145419

That's some amazing proof you have there.
I'm awed and amazed at the proofs.

Also why do you keep calling me an Intel shill?
I'm laughing at how much shit they are getting because they are a scummy as fuck company.

There is exactly no indication of this. To exploit meltdown, you have to be able to issue loads and stores to specific addresses, and JavaScript can't do that.

>> No.64145522

Literally in their statement. Besides tjay without prefetching and speculative execution performance would drop by at least an order of magnitude.

>> No.64145531

oh, I recongnize this one.
you're nvidia.
those that post speccy with "your own" radeon 290x to bitch about the inferior drivers. I love these guises the most.

>> No.64145548

It can. Every code can. With the root password you're in

>> No.64145570

Where's that proof tho?

>> No.64145572

How did they use JS for their proof of concept in the first whitepaper on this then?

>> No.64145766

>Facebook filename
Kill yourself, zuckercuck.

i figured out why you're here.
you must be tired.


THe issue is baked into the silicon

>> No.64145961

I showed you mines.
Now show me yours ;)
Oh wait, you have none.

>> No.64146022

Those are nice trips, but that isn't proof.

>> No.64146209
File: 52 KB, 365x444


+1 this - someone ansr pls

you moron ... win 7 is still getting support for 2 years meaning if there was a fix, w7 would get it too

>> No.64146270
keep on trying, ganbatte! faito!

>> No.64146303

I am waiting for you to post your supposed proof of AMD immunity to Spectre.
You haven't.

File: 65 KB, 726x781, holy_sheeeez.png


you got curious though, proof of what you on about? linus' post? well, he did btfo with that and it was awesome.
here, have another sip of that.

>> No.64146386

That is not proof.
That is just Linus being an ass and pointing it how awful Intel handled the news. (and rightfully so!)
Also, that says ARM, not AMD.
>> No.64146699
File: 212 KB, 793x307








what part of the "near zero risk" you don't get?

>> No.64146790

>> No.64146869
File: 188 KB, 552x530

Thank you, that's all I fucking wanted man.
I actually want to read this. I ain't no shill.

lmao Intel is hyper-fucked.

>> No.64146961
>> No.64147030
>> No.64147036

>> No.64147056

>> No.64147166

>use qx9660 for years
>people laugh at me for using old architecture
Who's laughing now?

