/ivg/ - Intel Vulnerability General

Last one hit the bump limit.

NEW INTEL CPU BUG THAT AFFECTS PRETTY MUCH ALL CRYPTOGRAPHIC APPLICATIONS:
openwall.com/lists/oss-security/2018/06/13/7

This affects FPU context switching, which now needs to be completely cleared because of state leaking!!

Intelfags on suicide watch, again.

Old:

Attached: intel.png (512x512, 35K)

Other urls found in this thread:

marc.info/?l=openbsd-tech&m=152895192209700
marc.info/?l=openbsd-misc&m=152883510311011&w=2
en.wikipedia.org/wiki/Loongson
github.com/ascendr/spectre-chrome
seclists.org/oss-sec/2018/q2/189
marc.info/?l=openbsd-misc&m=118296441702631
youtube.com/watch?v=UaQpvXSa4X8&feature=youtu.be&t=19m21s
warosu.org/g/thread/S66327917
youtube.com/watch?v=UaQpvXSa4X8&t=1132
twitter.com/NSFWRedditGif

And here I thought 2017 was a bad year for intlel kek

Apparently this was fixed a couple of years ago in Linux already

POC?

Attached: hackerman.jpg (500x500, 112K)

amd stocks are rising

Attached: 1528529481710.gif (528x555, 816K)

One bug was fixed, the FPU one.
There are SEVEN other bugs under embargo at the moment.

>it's been at last 3 months
>experienced people can pierce exploits from a barebones presentation in 5 hours
>the OpenBSD team can find (or obtain information) about this CVEs to patch them
wew lad, I wonder how fucked are most crypto exchanges by now

>be intel
>make chips with backdoors
>realize nobody is buying your 1-5% performance increase cpus
>twice the price they bought their cpu five years ago
>GREAT IDEA
>cuck the NSA and other spy agencies
>"leak" the backdoors to the public
>now they'll upgrade!
>right?
>goys?
>buy my over priced psuedo speed increased processors
>goys?!
top kek.

all thanks to you frogposter

what nonsense, intel never fixes anything and continues selling flawed chips. It'll soon be 2 years of this shit and they still make new chips with same vulnerabilities and nobody even sued them.

Just how fucked is hummanity because of Intel?
Will we ever recover and get Intel-free software that doesn't give shit about their jewish tricks and actually perform good on amd?

delid dis

Attached: 1500635558651.jpg (681x522, 83K)

>There are SEVEN other bugs under embargo at the moment
First I've heard of this- do you have any credible sources for this rumour?

>the intel hardware exploit level train has no stops
fuck yeah
gimme some more of those overpriced defective cpus (and a water chiller to cool it down)

Wew, another one already? In my mind, my Pentium G4560 is gradually looking more like pic related every time more vulnerabilities are announced. I really need to upgrade it to Ryzen.

Attached: 1525359495425.jpg (600x600, 24K)

from the man himself
marc.info/?l=openbsd-tech&m=152895192209700

and some of the autistic cocbsd fuckers continue to make fun of him.
he is doing the world a favor, now issue an apology like one of the autisic retards from the bsd conf the other day did
marc.info/?l=openbsd-misc&m=152883510311011&w=2
or stfu

The original source was a reputed German IT journal (Heise). They said there were 8 Spectre-like vulnerabilities in Intel CPUs currently under embargo.
People were not sure whether that was true. But a few days ago OpenBSD revealed that there is indeed at least one vulnerability. It's not a stretch to think that there are indeed 7 of them.
In fact, Theo predicted *TEN YEARS AGO* that there would be many vulnerabilities.

I wouldn't be surprised if there were in fact even more vulnerabilities to discover. It's likely that governments agencies, cyber-criminals, etc. are currently researching this.

It's so bad that OpenBSD is going to simply flush everything by default on Intel CPUs, and only revert the stuff when they confirm that there is no vulnerability.

This is a scandal equivalent to the emissions test cheating software in European cars. Intel has basically been cheating with performance, by doing optimizations that completely break security down (doing speculative execution past isolation boundaries).

>This affects FPU context switching, which now needs to be completely cleared because of state leaking!!

Lol which is completely a software issue, Enjoy your booner cores! slow and steady wins the race!

>pretending over half the shit released doesnt affect amd

Yeah security researchers don't exist/don't do any work.
Every CVE you see is a result from a company internal discovery and consequently disclosure/leaks.

>software issue
>lazy FPU context switching
How?

Only way that water chiller will make a difference is if you pour it under the IHS.

I've bought AMD since the 1990s.
My first CPU was an AM386.
Intel has always felt wrong.

>over half
hahahaha, you are so transparent, mr sheckelstein
but please, do post a list

>pretending intel

>Intel has basically been cheating with performance, by doing optimizations that completely break security down (doing speculative execution past isolation boundaries).

God smite these wicked semites
AMD rise from the ashes

Attached: 1513867939772.gif (111x150, 21K)

not a problem in linux as it uses eager fpu since 2016
I'm on amd--not a shill.

Biggest vulnerabilities affecting AMD CPUs are ones made up by an Intel funded Israel based cyber security firm that only offers 24hrs for a right of reply before publishing their "findings".

Freebsd is full of unstable people it seems. Their main promoter and hero "Freebsd girl" is a good example of this.

Theo actually confirms in his talk that AMD's architecture around cashing is vastly superior and almost goes so far as to say Intel are amateurs in comparison.

It's clear that Intel has been cutting corners on well known best practices. Either this is utter incompetence lettering marketing dictate engineering, or utter malice letting spooks dictate it.

Yes.

Because it doesn't.

>fell for indel meme
>spectre and meltdown reveiled
>Fuggg, but it's not that bad rrr-ight?
>now this shit happens

Never make the same mistake.

Btw what's stopping any hi tech chink company from rolling out their own cheap x86 like processors? inb4 patent laws

Attached: 1527891492698.jpg (722x349, 56K)

>Btw what's stopping any hi tech chink company from rolling out their own cheap x86 like processors? inb4 patent laws

They use a better architecture
en.wikipedia.org/wiki/Loongson

Fugg. Imagine 50$ chink package that performs on par with 400$ x86-64 bs.

I wanna see that video

>Btw what's stopping any hi tech chink company from rolling out their own cheap x86 like processors?
Chinks can't into high-tech manufacturing. Compare their RAM chips to South Korean for example.
They can steal and copy as much as they want, but at the end of the day they won't be able to manufacture the stuff properly.

OY VEY

Attached: 1527690603812.jpg (494x345, 29K)

Time to come home to the pre-botnet world, white man.

Attached: eb5e03ac73b37ec9e57a664e5fd9c3283dd9035c0daaf9b2eb5ea42caf470ec3.jpg (567x426, 87K)

The management engine is probably an intentional backdoor, but speculative execution bugs like Spectre and this FP issue are almost certainly just a result of prioritising speed and features over security concerns. It's fair to blame jewtel but it's also kind of the fault of consumers (especially the giant enterprise ones) for having that same mindset. Hopefully that's changing now that they're having to eat the costs of all these security disasters.

Attached: intel jew tactics.png (760x1978, 146K)

skylake X and the derivative xeons use the same cache arch that AMD had in bulldozer.

Shame the FX-9590 is the last and fastest CPU without a management engine

It would be 10x as we need a processor to be if there wasn't so much bloat at every level of computing.

ARM64 already exists and is supported by Win10, which can even run x86 programs through emulation.

Attached: win10 ARM win32 emulation.png (650x363, 124K)

but has anyone actually been hacked by these spectre memes and others? i have not heard anything yet but everyone says that these are really bad things.. someone would have done it already if it was as easy as people say

heh

> Theo predicted *TEN YEARS AGO* that there would be many vulnerabilities.
Plz gib sauce. Need new copypasta.

Attached: image.png (500x498, 58K)

Factually incorrect. Enjoy the vulnerabilities Intel shill.

>>This affects FPU context switching, which now needs to be completely cleared because of state leaking!!
>Lol which is completely a software issue, Enjoy your booner cores! slow and steady wins the race!
Why doesn't this affect AMD then hmmmmmmmmmmmmmmmmm?

Attached: saycheese.jpg (350x350, 35K)

Do you know of any prebuilt systems available outside of China? Would love to fuck about with a mips netbook

There were PoCs at the time proving it worked and was relatively simple to do, including through javascript. It's definitely not just theoretical.

github.com/ascendr/spectre-chrome

Those specific implementations probably won't work anymore due to various mitigations that have been introduced, but the bug is fundamentally still there and can be exposed again by a sufficiently creative approach.

STOP BEING SO ANTI-SEMITIC

Attached: 1487297768743.jpg (960x878, 125K)

> [...] other manufacturers (AMD) are not known to be affected.
seclists.org/oss-sec/2018/q2/189

OH NO NONONONO AHAAHHAAHAHAHAAHAH

What's his endgame?

Attached: 1497811003710.jpg (1000x1000, 119K)

I've ultrasparc t2 plus at work, how fucked am I?

Crashing the fabs

Intel fucked over the entire planet.

Literally never ever.

Is RHEL 7 vulnerable?

11 years ago actually

marc.info/?l=openbsd-misc&m=118296441702631

>These processors are buggy as hell, and some of these bugs don't just cause development/debugging problems, but will *ASSUREDLY* be exploitable from userland code.

>As I said before, hiding in this list are 20-30 bugs that cannot be worked around by operating systems, and will be potentially exploitable. I would bet a lot of money that at least 2-3 of them are.

>Loonux

Attached: Screenshot_20180615-083554.jpg (1440x2376, 451K)

(You)

noice

BASED

Attached: theo on intel 11 years ago.png (844x1424, 337K)

>the fix Increases performance
>only affects virtual hosts
wew it's fucking nothing you guys can go back to shilling AMD and falseflagging as Intel shills in other threads now

Attached: shitpostersneedtoleave.jpg (1280x720, 107K)

DELETE THIS ANTI-SEMITIC THREAD RIGHT NOW

Where do I sign up for the lawsuit?

Or say 3 good things about the Jewish people.
If you can't you're clearly a racist.

BIG
KHAZAR
MILKERS

Attached: mega milk rv.png (609x571, 259K)

With no yields!

>they make good fuel
>they make excelent skincare products
>they make decent fabric for ilumination applications

>so many claims
>no single source
Shit pic

youtube.com/watch?v=UaQpvXSa4X8&feature=youtu.be&t=19m21s
warosu.org/g/thread/S66327917

>2006
2006
>2006
2006

Attached: core_duo_errata__2006_01_21__full.gif (633x3277, 116K)

Source for 2?
By the way, 10 is bullshit

FUCKKKKKKKKKKKKK

>There are SEVEN other bugs under embargo at the moment.
>There are SEVEN other bugs
>SEVEN other bugs
>SEVEN other bugs under embargo

I can't take it anymore! AHHHHHH

Attached: skeleton chair.jpg (1280x1556, 434K)

Time to pay the piper.

Attached: Ovens-in-the-Auschwitz-crematorium.jpg (600x450, 92K)

youtube.com/watch?v=UaQpvXSa4X8&t=1132

mises, rothbard, friedman

I didn't understand that. What was he even shouting about? Why was he so upset about FreeBSD being under embargo?

Apparently he's under the embargo jurisdiction, though he isn't formally in the foundation staff or some shit like that.

for a long-time industry follower, these are already established facts, the only ones that need citation for any of these are relative newcomers to
The Game

and yes, you just lost

Gee thanks intel.

fuck man

>it's ok goy just compile your code using icl for better performance

Oy vey

Attached: 1500377406924.jpg (2083x1405, 462K)

>10 dollaros Starbucks gift card
Oh NONONON

>new
NSA would like a word with you

More like

Attached: 1528960412106.png (512x512, 30K)

Theo called them out for being corporate whores by signing NDAs with Intel.
Some FreeBSD guy tried to pretend that the FreeBSD Foundation is distinct from the FreeBSD Project.
Theo replied "whatever, don't know/don't care about the details of that arrangement".

That's when the autist, later identified as a member of the FreeBSD coc(k) committee, sperged out.

Holy fuck Intel sucks!

Was the $10 giftcard and the coasters really the only reason these advice were supposed to be followed?

everyone who knows anything about a computer, knows the core of it is the chipset, not the fucking cpu. intel shilling on dumb fags as usual

more like

Attached: lel.png (512x512, 33K)

intel should make recall

Do you have the link to the journal, lad?

And of all of those, only one or two where true and they weren't a big deal to begin.

>those cheap incentives
Intel is now jewing even the bribes?