'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign

Discussion in 'other security issues & news' started by Minimalist, Jan 2, 2018.

  1. Tinstaafl

    Tinstaafl Registered Member

    Joined:
    Jul 30, 2015
    Posts:
    965
    Location:
    USA
  2. guest

    guest Guest

    Mailing list message:
    Disable SMT/Hyperthreading in all Intel BIOSes
    "SMT is fundamentally broken"
    August 23, 2018

    https://marc.info/?l=openbsd-tech&m=153504937925732&w=2
     
  3. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Qubes OS also disabled SMT/HT by default:
    https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-043-2018.txt
     
  4. guest

    guest Guest

    Foreshadow, SGX & the Failure of Trusted Execution
    September 8, 2018
    https://www.darkreading.com/cloud/foreshadow-sgx-and-the-failure-of-trusted-execution/a/d-id/1332733
     
  5. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
  6. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    New SpecuCheck release:

    Link: https://github.com/ionescu007/SpecuCheck/releases/tag/v1.1.0

    Latest release with SSBD and L1TF support.

    Link: https://twitter.com/aionescu/status/1045831647730401280

    Link: https://twitter.com/aionescu/status/1045831916983803905
     
  7. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I ran this latest SpecuCheck, but I don't know if what I got is meaningful:
    SpecuCheck_01.JPG
     
  8. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    yeah I don't know if my results are good, bad or somewhere in between.
     

    Attached Files:

  9. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I compared mine to yours, and there are differences. But, what it means: I haven't a clue! But, I am not too concerned. ;)
     
  10. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Here is mine as it is currently:
    SpecuCheck.png
     
  11. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    It is not so user-friendly, for sure. All that I know is that green is good (whether answer is Yes or No) and red is bad. :cool::D

    Your SpecuCheck output shows that the system is missing several components (model-specific register (MSR)) from the microcode. The output is more technical as opposed to user-friendly, but you could always copy and paste certain parts, such as "SPEC_CTRL MSR (048h)". But even in that case, Intel documentation is sometimes lacking with the more current details.
    Your output seems to show all of the appropriate microcode related updates. Although it's missing the "SPEC_CTRL MSR (048h)" support similar to mine.
     
  12. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    A nice that SpecuCheck is still alive, with their last release in January I thought development was dead.
    There have been 2 microcode updates with sidechannel migitations so far, 1 after the original Spectre and one for SSBD and L1TF. It looks like WildByDesign and wat0114 only have the first microcode update, and Tarnak has both. Without the second, you don't have SSBD mitigations, but it looks like for L1TF there is still some OS migitation("With KVA Shadow and Invalid PTE Bit".) I don't know however if that is effective without the microcode update.
    The other red No's:
    -Unnecessary due lack of CPU vulnerability: the latest Intel CPU's are not vulnerable to these, so they dont need the mitigations.(Afaik they're only not vulnerable to these specific attacks, the design is still the same with all kinds of insecure speed features like the speculative execution and hyperthreading, so I wouldn't buy a new CPU because of this until they make major architectural changes.
    -Branch Prediction Migitations Optimized and Import Adress Table Optimizations: not sure about these ones, sounds similar to the PCID and INVPCID features of newer CPU's which allow for better performance. (Those 2 features are the ones InSpectre looks for.)
    -SPEC_CTRL_MSR (048h): I don't know what this is. I have the second microcode update for SSBD/L1TF but this is also a No for me.
     
  13. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
  14. guest

    guest Guest

    Spectre and Meltdown Hardware Protection Added to Intel's 9th Gen CPUs
    October 8, 2018
    https://www.bleepingcomputer.com/ne...ware-protection-added-to-intels-9th-gen-cpus/
     
  15. guest

    guest Guest

    SpecuCheck v1.1.1 Released (October 16, 2018)
    Download
     
  16. guest

    guest Guest

    MIT researchers say memory splitting breakthrough could prevent another Meltdown or Spectre
    October 17, 2018
    https://techcrunch.com/2018/10/17/m...uld-prevent-another-meltdown-or-spectre-flaw/
     
  17. guest

    guest Guest

    Windows 10 19H1 will reduce the impact of Spectre Mitigation to “noise level”
    October 19, 2018
    https://mspoweruser.com/windows-10-19h1-will-reduce-the-impact-of-spectre-mitigation-to-noise-level/
     
  18. guest

    guest Guest

    The Intel Microcode Boot Loader Protects Older CPUs From Spectre
    November 12, 2018
    https://www.bleepingcomputer.com/ne...boot-loader-protects-older-cpus-from-spectre/
     
  19. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
  20. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Spectre, Meltdown researchers unveil 7 more speculative execution attacks
    https://arstechnica.com/gadgets/201...-unveil-7-more-speculative-execution-attacks/
     
  21. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    More Spectre/Meltdown-Like Attacks
    https://www.schneier.com/blog/archives/2018/11/more_spectremel.html
     
  22. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    519
    Location:
    Bulgaria
  23. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    New side-channel leak: Boffins bash operating system page caches until they spill secrets
    https://www.theregister.co.uk/2019/01/05/boffins_beat_page_cache/
     
  24. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Linux Kernel Spectre Protection Changes to Boost App Performance
    https://www.bleepingcomputer.com/ne...-protection-changes-to-boost-app-performance/
     
  25. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    'This collaboration is absolutely critical going forward'... One positive thing about Meltdown CPU hole? At least it put aside tech rivalries...
    https://www.theregister.co.uk/2019/02/15/vulnerability_experts_blab/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.