It's intel's bug, they promised a certain processor speed, shouldn't it be their responsibility to replace it since their own security oversight resulted in the hardware not working as advertised?
Did you expect the same from intel/amd when those bugs came out? Is it different from this situation?
How have they advertised that? Was it clock frequency? Their mitigations mean it still runs at that clock frequency.
New CPUs are largely immune to the specific attacks that were published before they were designed. But we aren't gonna get a fast CPU without sidechannels and IMO it's not possible in theory to build a branch predictor that never makes potentially exploitable mispredictions.
In a sense this doesn't change your point but I wanted to take the opportunity to point this out. "This CPU is vulnerable to attack X" just means researchers have found an exploit in practice, which we already knew in theory was there.
This wasn't the expectation before Spectre/Meltdown but now we live in a world where you need to assume a degradation in your CPU's effective performance as we learn about its vulnerabilities and need to apply software workarounds.
I am building "one mitigation to rule them all" called Address Space Isolation but this doesn't fundamentally remove that fact, it just means that when we learn about a CPU's vulns we don't have to build a new mitigation we just have to change the settings on the existing one (and it should be more efficient than the bespoke one would be).
I believe the Mill hardware design would be immune by design because the hardware is in-order (relying on other trickery for its performance). Of course, it's still vaporware, but the noises made have been fairly competent.
So in some ways, yes, but in other ways, what if you didn't need a branch predictor in the CPU.
https://millcomputing.com/blog/wp-content/uploads/2018/01/Sp...
Well yes you can dodge this problem by not having a branch predictor but note the way I formulated my claim ;)
Following the same logic: old phones, even iphones can be hacked. Should manufacturers replace the hardware?
The warranty is not that long, and I think the parent comment is talking about 6+ year old iphones that are definitely out of warranty.
If those should get replaced, surely that means each person buys one iPhone in their life, and then just gets free replacements forever, leading to the initial cost of the phone having to go up a lot to account for that.
There is no such thing as secure lock. Any lock could be open without original key. The difference is in the amount of effort.
Still baffles me that KIA sold cars which can be driven away using screwdriver and USB cable.
These in fact do exist, but they have properties unsuitable for many use cases, such as taking 8-24 hours to open if you lose the key/combination or a mechanical fault occurs, and being part of a system so heavy the floor beneath them have to be constructed to support the weight. (A friend of mine was a master locksmith for many years and worked on such locks, mostly for government contracts.)
In case of a lockout often the easiest way to open them is a brute force attack using a device called an autodialer.
Maybe you live in a country where car thieves hack into cars left and right. Maybe you live in a country where thieves just tow your car in the middle of the day and don't care about your locks at all. Do you expect car maker to ship you free fixes against every scenario? Security is a spectrum. Make your police better if you don't like it.
/controversial opinion