About speculative execution vulnerabilities in ARM-based and Intel CPUs
support.apple.com
support.apple.com
These are the processors found in Apple products.
Yesterday, there were comments [edit: on HN] about the Intel PR announcement that were critical of the fact that Intel name-dropped AMD in what was thought to be an attempt to deflect the issue from the Intel brand.
[1] http://gs.statcounter.com/macos-version-market-share/desktop...
Clear as mud.
If Apple was able to patch macOS in the ~6 month window since the issue was discovered why were they unable to patch Safari?
Same question for Chrome and Firefox. Surely Google knew about it and hopefully they contacted Mozilla. It seems like the scope of the fixes for Chrome and Firefox are the same.
Does it really take six months to do dev & QA for a fix like this? Wasn't the plan to disclose this to the public in January anyways?
This is incredibly deceptive, because web workloads are precisely the sort not expected to be impacted by Meltdown most. As I've written elsewhere, it's syscall heavy workloads targeting fast devices, like database software on PCIe SSDs, that will suffer the greatest slowdowns.
That's not exactly a common scenario for macOS, much less iOS devices.
It's fair to call for benchmarks that are more representative of common workloads, not less representative.
Since I work on network attached storage for video editing, I'm acutely aware of how much slowing down a few simple syscalls by just a little bit can be for certain very commonly used applications on macOS.
I'm going to go out on a limb here and say that a NAS isn't slowing things down "just a little bit". It'll be more on the order of a million times slower, for those operations.
It's always nice to keep this popular latency table in mind: http://norvig.com/21-days.html#answers
*Edit: Also potential reimbursements/compensations and manageing them.
Edit2: What if customers decided to return en mase their new iphone X or macbook they got for christmas?
Not everything is a conspiracy theory.
Could this “check later” speculative approach similar to Intel’s explain Apple’s great performance advantage over other ARM CPUs?
No. Speculative execution is not unique to Apple's SoC designs; it's present in other ARM cores as well.
What about macOS 10.12 and earlier versions?
Sierra and El Capitan is covered too.
https://support.apple.com/en-us/HT208331 - see Kernel entries.
Edit: I see, there is a confusing typo in om2's comment (it should be 10.12.6 not 10.12.7). I am wondering why this update does not show up in my list of installed updates. What a mess.
https://support.apple.com/downloads/macos
Perhaps you're referring to a release on Dec 6 labeled as "Security Update 2017-002 10.12.6," which does not appear to include the Meltdown patch for Sierra.
If you want to check that you have installed this update, you can use the following command:
$ system_profiler | grep 'Security Update 2017-002'Haven’t there been JavaScript POCs for Meltdown? That’s already patched and AFAIK there’s nothing for Spectre yet, but this is still a little disingenuous.
Apple and Google should want old devices to be patched, to avoid teaching consumers that their devices cannot be trusted.
Until Google takes the stand and actually forces OEMs to update, nothing will ever change.
Not for existing devices, nor for Treble certified ones.
Updates are only for rich people able to pay 500€+ for flagship devices every three years.
Ultimately the problem with Android driver security is that Qualcomm has no interest in it, and won't until some form of legislation from a large territory such as the US, EU or China forces their hand on it.
So unless Google changes their mind, users will get the same amount of updates as they are getting now on non-Treble devices.
And only when you buy it on day one:
Pixel phones get security updates for at least 3 years from when the device first became available on the Google Store, or at least 18 months from when the Google Store last sold the device, whichever is longer. After that, we can't guarantee more updates.
Source:
Additionally not all countries are deemed worthy of being able to buy Pixel.
I am no expert in any way but would like to know how did they "mitigated" this without a serious performance hit.
Besides, syscalls have historically been slow on OS X; back when the kernel was 32-bit the kernel and user space had completely separate address spaces (unlike windows and default Linux) and I’ll bet even most power users never realized.
Apple decided that heavy userspace execution and web performance are representative of common workloads. You are welcome to argue for a different kind of workload. As it stands now, at best you're implying that it's common for users to execute syscalls in a loop.
Do you think common users execute guassian blurs in a loop and ray tracers before perfoming rigid body physics in their "common workloads" ? As you said, I know I am welcome to argue for a different kind of workload, specially when I am being taken for a fool.
As for what common users execute, based on my observations over the years it's mostly web browsing. However my personal vision of common workloads is a distraction. I have made no claims to know common workloads. I merely stated that Apple has chosen a particular set to be representative.
Kernel
Available for: macOS High Sierra 10.13.1, macOS Sierra 10.12.6, OS X El Capitan 10.11.6
Impact: An application may be able to read kernel memory
Description: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
CVE-2017-5754: Jann Horn of Google Project Zero, Werner Haas and Thomas Prescher of Cyberus Technology GmbH, and Daniel Gruss, Moritz Lipp, Stefan Mangard and Michael Schwarz from Graz University of TechnologyHas it been proven that Meltdown can affect ARM processors, or is this Intel speculation?
Did Google name it Spectre after the the James Bond movie?
And I thought AMD put out a release saying they are not affected.
It would be a huge surprise if ARM were somehow immune.
https://googleprojectzero.blogspot.com/2018/01/reading-privi...
disclaimer: I work at Google, but not on Project Zero.
Is it possible that they don’t do speculative execution?
> Apple Watch is not affected by Meltdown.
i.e. by the lemma of overly specific dementi it follows that Apple Watch is affected by Spectre.
It sounds like it is potentially affected by Spectre, especially since they say they will be continuing to develop mitigations for WatchOS.
The surprising thing to me is that they patched iOS to mitigate Meltdown. Before now, I thought it was only Intel chips that were affected by Meltdown, but I guess Apple's own A-series processors are affected too.
For context, the only phones that are not being supported by the latest patch are iPhones introduced before 2013.
Even my third party podcast client supports exporting to OPML.
a) The article above doesn't mention it (specifically says 10.13), and
b) There are no updates available for my mac.
known by whom? Apple? Then say "we do not know of any exploits". Is the answer different for the NSA? Who the f knows?