Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed.
rockSlayer@lemmy.blahaj.zone 3 weeks agoI don’t see AMD on that list. Do you?
Lashing out at me was unnecessary. I was pointing out that there are 2 catastrophic vulnerabilities that are going to be present in every chip that meets your criteria.
I’m not defending the IME or the PSP. The most generous thing I can say about them is that they are unnecessary. I’m pointing out that the chips that you want to use have been unsupported for so long that they have catastrophic vulnerabilities that have never even been attempted to be patched. There are more catastrophic vulnerabilities than just Spectre and Meltdown.
evenwicht@lemmy.sdf.org 3 weeks ago
It was an attack on your bullshit. Not on you personally.
And I was pointing out that you are wrong.
You are advocating for chips that are /more/ vulnerable, not less. You are advocating for chips with a much larger attack surface and unknown vulns. Overall, you are giving poor advice from an infosec standpoint.
I’m waiting.
rockSlayer@lemmy.blahaj.zone 3 weeks ago
No, you weren’t. You were being pedantic. AMD will have Spectre. Intel will have Spectre and Meltdown. 2 vulnerabilities.
No, I wasn’t. Stop putting words in my mouth. Unless you know how to write microcode, I have serious doubts that you are capable of successfully patching the vulnerabilities on those chips.
Do whatever you want. I don’t care.
evenwicht@lemmy.sdf.org 3 weeks ago
If you don’t like the facts, what more is there to say? The facts failed to support your claims. If you will not let the facts shape your world view, then it’s on you to go off and find different facts.
Nonsense.
How are you still failing grasp this? The fix was made. And it was done without writing microcode. You don’t even have to patch Meltdown on chips unaffected by Meltdown (AMD). The spychip failed to protect from both Meltdown and Spectre.
Patching is not the only way to control for a vuln. I am not going to give you the whole infosec discipline here in this thread. There are many ways to controlling for a vuln apart from patching. Depending on your threat model and use cases, there may be no need to do any control.
rockSlayer@lemmy.blahaj.zone 3 weeks ago
You act like you’re the only one that understands information security. I took a security class for my computer science degree too. Productive conversation cannot be had when you strut around arrogantly dismissing everyone that disagrees with you.
Meltdown was a microcode patch. Spectre was a kernel patch, so in firmware. Only AMD bothered to fix chips that fit within your timeframe. The fix has not been made for the chips you want to use.
You aren’t going to stop branch prediction with clever tricks. These are hardware level flaws. Patching is the only way to completely mitigate these flaws.