This all simply makes all our IT related work just kids playing make-pretend security.
I am literally trying to figure out what other processors exist that can be used in everyday BSD/Linux work. Sparc? Some ARM branch? Any suggestions welcome.
This all simply makes all our IT related work just kids playing make-pretend security.
I am literally trying to figure out what other processors exist that can be used in everyday BSD/Linux work. Sparc? Some ARM branch? Any suggestions welcome.
Instead of false promises we need to develop better engineering: verification, computational math, etc. And also laws - no free/open license in the world will stop companies from tracking, but fine as big as 4% of total revenue (EU GDPR) will make them oblige.
In a world where personal computers only ran code the user could safely trust, these exploits would only be full attack vectors when applied to multi-tenant computing environments.
I'm not arguing that FOSS systems are inherently more secure than closed systems, but when it comes to exploits that require arbitrary code execution to be effective, Stallman really was/is right. Between a NoScript browser extension and a system whose source code is entirely available to you, you've basically got Meltdown/Spectre immunity.
I personally trust FOSS software more not to do dumb things (like, hopefully my password manager doesn't report all my passwords to NSA), but simply being FOSS doesn't make it any more secure :)
Reproducible builds (https://reproducible-builds.org/) is an initiative to fix that part of the problem. With reproducible builds, a third party with the same source code and compiler will get an identical binary, so we can have independent entities certifying that the code you download with apt-get was built from the corresponding source code.
My Windows 10 machine got the Meltdown patch yesterday, in an out-of-band, undelayable update. Then it restarted itself during the night and this morning it's secure. My Ubuntu laptop is still unpatched and I'm not sure when the 4.15 upgrade will come to 16.04.
Out of order variants are still in the design stage, so they may come up with a way to isolate or invalidate speculation effects on branch misprediction.
It does show the problem of all theorem provers: they are only as good as the specification.
The specification does not conform to the user's expectations or documentation. It's flawed.
Theorem provers can only prove that the code conforms to the specification, not to the user's expectations or documentation. They can be very helpful, but they aren't magic and can't interpret non-formal specifications.
His thoughts on cloud computing, however, are very much worth listening to.
https://stallman.org/stallman-computing.html
Scroll down to the point titled "I am careful in how I use the Internet."
Of course on some occasions the software isn't going to be able to compensate, but Stallman's ideas about why free software is important are grounded in some very practical realities.
Ever see a wire on pcb boards going from one end of the board to another? Thats the hardware equivalent of a: "we can't fix this properly, but we can hack a fix on until we can fix it right in the next revision" hack.
https://www.cadence.com/content/cadence-www/global/en_US/hom...
It'll cost you ~$1M and run at a few MHz.
I work for a company that works with Intel on new things. Lets just say the FPGA's they use are... really expensive, and despite being capable of simulating a design fast, are still very slow.
By expensive I found out $20 million per FPGA simulator was on the low end. And I think that would simulate at the rate of about 10mhz for the amount of transistors/internal setup present.
Fpgas are cool, but a poor choice for fixing this issue.
You could probably do it for up to an 80386 with some $400ish dollar FPGA's.
If Intel were open about yes, even the microcode, maybe we would've seen this issue sooner - more openly. What we have is paltry in comparison to the way it would be if, in a Stallman universe, software was 100% open, always.
If AMD can fix something like this, Stallman would say the end user should be able to as well. He has a point, and the number of useless IoT devices we're already seeing is testament to that fact.
Given that Spectre is trivially exploitable from motherfucking JavaScript, this bit of craziness turns out to have concealed much wisdom.
With some encouraging sentences to keep on making the world a better place.
He felt honored. He asked me to post this for him.
"Now that you recognize these problems are real, how about joining in the work to fix them? See gnu.org/help for a list of many different kinds of work that we need (programming is just one of many), then pick one and help!"
This is a specific side-channel attack in a super complicated system. Even if we had OSS x86/64 processors, this more similar to the protocol issues found in openssl.
Richard Stallman was right and I wish we would learn to listen but I doubt that will happen.
Bastard had the nerve to tell Alexander to "stand a little out of my sun."
Total nutjob. No respect for wealth and power whatsoever.