Intel won’t release Spectre patches for some older chips after all
liliputing.com
liliputing.com
According to this document, make sure to read your CPU's model numbers carefully. It doesn't reflect well on Intel that the line does not appear to be drawn based on technical capability, but apparently on contractual obligations.
Many CPUs in the unsupported list still make very serviceable hardware in 2018. It's a shame a security issue will only add to their obsoletion, or make people using this hardware more vulnerable. Spectre variant 2 is difficult to exploit in practice, but that sounds like some famous last words.
[1]: https://newsroom.intel.com/wp-content/uploads/sites/11/2018/...
[2]: On page 8
[3]: On page 16
And yes, by saying this, in part I'm hoping to put it into people's minds. And, if there's enough of that, into pressure on Intel.
P.S. My concern extends to what may happen to coverage if/when succeeding rounds of fixes are needed. In general, we don't appear to be done with this class of problem in extant products.
Not that Apple's "the solution". But lack of support will prompt people to consider alternatives.
Both Intel and Apple have large talent pools of excellent silicon and lithography engineers but that hardly makes them immune to bugs, and some bugs will end up being vulnerabilities.
And, Apple's silicon development appears to be top-notch. In addition, the company professes and demonstrates some ongoing concern about security.
So, depending on Apple's ongoing hardware developments, Intel may face technical pressures on the security front with respect to processors and SoC.
And Intel needs to match its technical developments with demonstrated concern for its users' security and not allowing its products to compromise same.
Anyway... I hope the pressure stays on Intel. Going through the current process -- not just with Intel, but with system vendors -- wondering whether my several year old but still quite functional systems will be updated, and when.
And right before that, the struggle to know what to do about the ME vulnerabilities.
Some people have to be getting kind of tired of this. And now to carry continued tension, waiting for the next shoe to drop.
In the phone world, Apple users don't seem to worry as much as Android users with respect to vulnerabilities. Because Apple usually patches them fairly quickly, and Apple also has used its muscle to bypass carriers' horrendously bad update support as witnessed in the Android world.
Computer users aren't going to want to worry whether they're going to get a full life out of their computer, or have to stop using it for X months until a problem gets patched.
Right now, most of them are pretty oblivious to the current chip problems. These problems start turning into active exploits, and that's going to change.
Ok. Ramble over.
Saw the headline and my heart sank, but I got a lucky dodge on this. Bought a W3680 because at the time, I couldn't find a W3690 at a reasonable price (from what I could tell they were a top choice for people refreshing their Mac Pros?). Maybe I'll squeeze another 7 years from this X58 machine yet!
Well that's the thing - they are the same thing! The difference between Gulftown and Westmere-EP seems to be entirely marketing, but this marketing difference now results in patching difference.
But for people wedded to that platform... not much room to move. :/
The 2012 Mac Pros, in particular, were still being sold less than 5 years ago, so this means it's still officially supported by Apple. I wonder if there's some awkward conversations happening between the two companies about that.
Fortunately, it's possible to upgrade the CPU in a Mac Pro to a newer part which is still supported by Intel.
Freedom's last holdout now are Coreboot ARM machines like the latest ARM Chromebooks.
RISC-V is already faster. It just needs better fabs.
I assure you there is no working libre microcode for intel CPUs and it seems far more likely people will successfully focus their efforts on open source hardware before being able to successfully replace substantial microcode of complex closed source hardware.
In "libre" EFI mods they tend to disable ME as well, maybe you were confusing that with microcode?
One of its omissions is that it excludes microcode ROM updates that can be inserted at power on by the BIOS
As I understand it. The CPU's of that era are old enough that they can run without updated microcode being inserted either at system bootup or operating system boot time
Not having microcode blobs in the EFI doesn't magically mean your CPU doesn't use microcode or doesn't need patched versions to stay secure as in this case.
I do find it a little deceptive with some of these "libre" projects where they draw an arbitrary box around something, evict all proprietary blobs from it and then announce victory despite it operating underneath a whole load of other blobs that could easily subvert it. However I suspect the intent behind evicting microcode from libreboot was more due to it being a redundant task for EFI today.
I will never buy another Intel CPU, fuck you very much Intel.
If you have an old macbook you might want to check that list, the various flavours of C2Duos on that list were pretty common.
AMD originally acknowledged vulnerability to one of the Spectre variants (GPZ variant 1), but stated that vulnerability to another (GPZ variant 2) had not been demonstrated on AMD processors, claiming it posed a "near zero risk of exploitation" due to differences in AMD architecture. In an update nine days later, AMD said that "GPZ Variant 2…is applicable to AMD processors" and defined upcoming steps to mitigate the threat. Several sources took AMD's news of the vulnerability to GPZ variant 2 as a change from AMD's prior claim, though AMD maintained that their position had not changed.
A shame about Bloomfield and Gulftown, but the rest of the products seem to be firmly in the legacy/obsolete category.