Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed.
evenwicht@lemmy.sdf.org 17 hours ago“Meltdown affects Intel x86 microprocessors, IBM Power microprocessors,[1] and some ARM-based microprocessors”
I don’t see AMD on that list. Do you?
“At the time of disclosure (2018), this included all devices running any but the most recent and patched versions of iOS,[5] Linux,[6][7] macOS,[5] or Windows.”
So this vuln can be fixed by patching OS kernels, and your reaction is to switch to a CPU that runs embedded closed-source software controlled by a corporate third party who decides what is authorized to execute on your own system? You can fix the problem with or without being nannied.
Spectre affected “All pre-2019 microprocessors”. So no, the spy chip did not protect you. Intel injected the spychip from 2008 forward and AMD did it from 2013 forward.
More generally, it’s not smart infosec to introduce complexity. It’s profoundly naive to stick a big attack surface in the core of your CPU. I think it’s quite well established that vulns exploit defects, and defects are proportional to complexity. Signing up for a closed source blob in the core of your processor is far from wise.
The /chase the shiny/ mentality neglects the fact that you sign up for the worst kind of vulns – the unknown variety. With old gear the vulns are more of the known variety, which you have a fighting chance of controlling for.
rockSlayer@lemmy.blahaj.zone 16 hours ago
Lashing out at me was unnecessary. I was pointing out that there are 2 catastrophic vulnerabilities that are going to be present in every chip that meets your criteria.
I’m not defending the IME or the PSP. The most generous thing I can say about them is that they are unnecessary. I’m pointing out that the chips that you want to use have been unsupported for so long that they have catastrophic vulnerabilities that have never even been attempted to be patched. There are more catastrophic vulnerabilities than just Spectre and Meltdown.
evenwicht@lemmy.sdf.org 7 hours ago
It was an attack on your bullshit. Not on you personally.
And I was pointing out that you are wrong.
You are advocating for chips that are /more/ vulnerable, not less. You are advocating for chips with a much larger attack surface and unknown vulns. Overall, you are giving poor advice from an infosec standpoint.
I’m waiting.
rockSlayer@lemmy.blahaj.zone 48 minutes ago
No, you weren’t. You were being pedantic. AMD will have Spectre. Intel will have Spectre and Meltdown. 2 vulnerabilities.
No, I wasn’t. Stop putting words in my mouth. Unless you know how to write microcode, I have serious doubts that you are capable of successfully patching the vulnerabilities on those chips.
Do whatever you want. I don’t care.
evenwicht@lemmy.sdf.org 5 minutes ago
If you don’t like the facts, what more is there to say? The facts failed to support your claims. If you will not let the facts shape your world view, then it’s on you to go off and find different facts.
Nonsense.
How are you still failing grasp this? The fix was made. And it was done without writing microcode. You don’t even have to patch Meltdown on chips unaffected by Meltdown (AMD). The spychip failed to protect from both Meltdown and Spectre.
Patching is not the only way to control for a vuln. I am not going to give you the whole infosec discipline here in this thread. There are many ways to controlling for a vuln apart from patching. Depending on your threat model and use cases, there may be no need to do any control.