New AMD side channel attacks discovered, impacts Zen architecture
tomshardware.com
tomshardware.com
Designing & manufacturing computer chips is hard af, having worked in semiconductor manufacturing for over 12 years (primarily on the backend side of the Fab).
Edit: Redacting some specifics
Perhaps videos such as these are shining a positive light on the entire semiconductor goodwill: https://www.youtube.com/watch?v=f0gMdGrVteI
Jim talks about it at this mark in this presentation: https://youtu.be/Qnl7--MvNAM?t=784
Just amazing. I wish a newer video explaining more recent technologies was available.
I'm not sure I agree. If by 'cool' you mean along the lines of receiving respect and admiration from others because, while they don't really understand the actual specifics of what you do, they have a general idea and it's celebrated widely, then I don't think we want that happening in semi space.
It looks to me that it's happened already in software development, and I don't think the end result of that is net-positive.
I think that when people are passionate about what they do, and do it because they're passionate about it, the end results tend to be better than if they're doing it because other people will give them recognition.
I'm not saying this is something that happens all the time, and you can argue that I'm being elitest, snobby, or annoyed that the 'cool kids' have come into my playground and are playing with my toys, all of which would be valid positions to take. I do think that with all communities, they're very different when they have smaller appeal to when they have wider appeal.
Niche communities are not without their problems (and the toxicity that can happen in them cannot be understated), but I personally prefer them, and believe the output is generally of a higher quality, than communities with wider appeal.
I am not optimistic. "Semiconductor company" ==> high capitalization (expensive processes) ==> fertile ground for lawsuits and attacks.
As long as a slightest mistake has a potential to turn into multi-million-loss lawsuits, it will never be cool. Is it easy to be cool walking a tightrope between two skyscrapers? Not for many I'd guess.
BTW it is the same for non-semi companies (like OEMs), except that volumes of a given single product are generally lower, so mistakes are more bounded.
I've written in-depth about why "don't click untrusted links" is unhelpful: see https://xmppwocky.net/blog.py?page=22
Intel in the P4 era is a lot different to now. P4 was an engineering mistake. And it wasn't Cornoe that saved that, it was Pat Gelsinger's Pentium M or Banias / Dothan.
The current ( or past ) Intel issues isn't engineering, they have amazing engineers. It is lying. Blatant lies that were fed from Sales and Marketing all the way to their C-Level. That is what happen when a successful company were driven by Sales and Marketing people.
The story I've heard was that P4 was a management mistake. Some engineers claimed they surely understood that the limits existed, but the management believed that the only thing that's sellable is a bigger number of GHz. So the engineers got the goal to make a processor architecture for 10 GHz, and apparently P4 was made for that (long pipelines) and it was known that on lower number of GHz the architecture performed worse. But 10 GHz was unachievable because physics can't be cheated (the chips would simply melt without some special cooling that was also not sellable), so P4 architecture was never driven with the clock speeds for which it was designed.
> We are aware of a new white paper that claims potential security exploits in AMD CPUs, whereby a malicious actor could manipulate a cache-related feature to potentially transmit user data in an unintended way. The researchers then pair this data path with known and mitigated software or speculative execution side channel vulnerabilities. AMD believes these are not new speculation-based attacks.
> AMD continues to recommend the following best practices to help mitigate against side-channel issues:
> Keeping your operating system up-to-date by operating at the latest version revisions of platform software and firmware, which include existing mitigations for speculation-based vulnerabilities > Following secure coding methodologies Implementing the latest patched versions of critical libraries, including those susceptible to side channel attacks Utilizing safe computer practices and running antivirus software
Also, they say they 'believe' it isn't new, and that word is used for a reason - it isn't legally binding. It is a lot different than saying "It isn't new."
Finally, the advice they give is akin to giving general advice for a Ford vehicle: "Change the oil every 3500 miles."
Generalized statements that mean nothing.
This looks to be an intentionally obfuscated response.
Many Spectre-type flaws are essentially about an OS process reading/writing it's own memory — which it is naturally expected to have access to. Of course, browser developers weren't prepared for that, but they also were not prepared for gzip-bombs...
I assume, that mitigations [1] suggested by AMD in 2018 are sufficient to protect against this (and all other) Spectre flavors on AMD CPUs, in which case there is really nothing new going on here.
1: https://developer.amd.com/wp-content/resources/90343-B_Softw...
See https://googleprojectzero.blogspot.com/2020/02/escaping-chro....
The issue with Spectre is about an OS process (or kernel) reading its own memory - this is why in contrast to Meltdown it can't be fully fixed by CPU microcode or firmware updates, it requires mitigation in any code that enforces security boundaries, such as kernels or sandboxing VMs.
> ... a malicious actor could manipulate a cache-related feature to potentially transmit user data in an unintended way. The researchers then pair this data path with known and mitigated software or speculative execution side channel vulnerabilities. AMD believes these are not new speculation-based attacks.
They are explaining why they don't believe it is new, it's because they don't use a new speculative execution. AND if all the old ones were patched, all a customer would have to do to protect themselves is keep their system up to date.
Sure the PR statement isn't legally binding (as nearly all PR statements are designed), but they left a very clear explanation. It does not at all appear intended to mislead.
Yes, PR is covering their butts with believe. This is a response PR; it needs to go out within a couple of days tops, but within 24 hours of the report is best. That's not enough time to confirm the new claims or that the speculative claims are existing. This PR say, yes, we know about this; we triaged it, and we'll get back to you later; please stop calling about it.
Expect a more thorough response, with more certainty in probably a few weeks; although, I dunno AMDs usual timelines on this sort of thing.
So, no, it's not a nothingburger at all.
It is a detailed research work that anticipates a potential issue, suggests solutions and explains undocumented processor features.
These news are Intel sponsored. https://twitter.com/HardwareUnboxed/status/12360799707298652...
Also the release does not quality as a new vulnerability vector like Spectre, just a new attack against a previously mitigated vulnerability. It honestly looks to me like anattempt to stop the AMD momentum.
FD: The fastest processor I own is a 16 core Xeon, and is great. However, I have invested in AMD stock over the last year. I have a lot of respect for Intel engineering, but the AMD roadmap just looks stronger between now and 2022.
Not good and leaked information about the manner in which a process is accessing memory is probably useful to some attacker out there, but thankfully it's not even in the same class as the actual memory content disclosure vulnerabilities..
My team at work has been snickering for two years about serious memory problems on a system our code partially replaces. I did not participate (see above).
Guess what I've spent the last few weeks working on? Go ahead, guess.
So AMD vs Intel is very personal for them.
In general, AMD processors have fewer issues. Is that bad? Why bring others down instead of bring yourself up.
They need to feel justified in their choice and it drives these crazy positions on CPU/GPU/Motherboard vendor.
I'm just glad we still have multiple viable vendors to choose from.
Why would this be the one topic about which people aren't tribal? There are people with Intel tattoos, same with AMD. They're frequently called "team blue" and "team red". People like to pick sides and belong to camps, and that's not changing.
But I couldn't get past "Take A Way".
Take... A... Way... Take a way. Take exactly one way. A way to take. I have three ways, you get to take one. Need a way? Take a way! Feel free to take a way from the way jar. Life finds a way... and then takes it.