trickery.net  

Go Back   trickery.net > Technical > Hardware

Reply
 
Thread Tools
Old 04-Jan-2018, 09:31   #31
EvilGrin
account shared with 10 people
EvilGrin's Avatar
Join Date: Oct 2003
Location: Lancs, UK.
Posts: 7,933
EvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond repute
Quote:
Originally Posted by Lungboy View Post
Spectre and Meltdown.
Now has a website and logos so we're fucked.

https://meltdownattack.com

Although I do love the angry ghost with the stick logo for spectre.
__________________
Edugeek - Techies in Education!
EvilGrin is offline  
Send a message via ICQ to EvilGrin Send a message via AIM to EvilGrin Send a message via MSN to EvilGrin Send a message via Yahoo to EvilGrin  EvilGrinUK 
Reply With Quote
Old 04-Jan-2018, 09:35   #32
GroovYF
Octave Doctor
GroovYF's Avatar
Join Date: Oct 2003
Location: Halifax
Posts: 23,619
GroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond reputeGroovYF has a reputation beyond repute
https://twitter.com/misc0110/status/948706387491786752
__________________
photoblog
GroovYF is offline  
 groovyf 
Reply With Quote
Old 04-Jan-2018, 09:41   #33
The Dark One
meh
The Dark One's Avatar
Join Date: Oct 2003
Posts: 8,109
The Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond reputeThe Dark One has a reputation beyond repute
So AMDís stance has changed from near zero chance to, itíll be fine when OSís are patched?

Also seems itíll likely require an local exploit but poses most risk in VM environments ?
The Dark One is offline  
Reply With Quote
Old 04-Jan-2018, 09:45   #34
EvilGrin
account shared with 10 people
EvilGrin's Avatar
Join Date: Oct 2003
Location: Lancs, UK.
Posts: 7,933
EvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond repute
Meltdown = Intel only. Allows escaping from VMs and compromising OS's.
Spectre = Application level exploit. Allows escaping from sandboxing (e.g. browsers). Affects all CPUs.

Meltdown is the far more serious issue.
__________________
Edugeek - Techies in Education!
EvilGrin is offline  
Send a message via ICQ to EvilGrin Send a message via AIM to EvilGrin Send a message via MSN to EvilGrin Send a message via Yahoo to EvilGrin  EvilGrinUK 
Reply With Quote
Old 04-Jan-2018, 09:54   #35
Scrobbs
Sunnyvale Supervisor
Scrobbs's Avatar
Join Date: Oct 2003
Location: In the pipe, five by five.
Posts: 16,207
Scrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond reputeScrobbs has a reputation beyond repute
Quote:
Originally Posted by Lungboy View Post
Spectre and Meltdown.
One of the single most annoying trends in infosuck - naming bugs and giving it a logo.

Another is 'cyber'. Death to all users of such.
__________________
http://bit.ly/debatethebill
Scrobbs is online now  
Reply With Quote
Old 04-Jan-2018, 10:39   #36
Solex
You're the Victim
Solex's Avatar
Join Date: Jun 2004
Location: Manchester
Posts: 4,504
Solex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond repute
Quote:
Originally Posted by Scrobbs View Post
One of the single most annoying trends in infosuck - naming bugs and giving it a logo.

Another is 'cyber'. Death to all users of such.
Yeah it's like they rush to make a cute logo to get in the news. Fucking roasters.
Solex is offline  
 THE SOLEX 
Reply With Quote
Old 04-Jan-2018, 10:41   #37
Solex
You're the Victim
Solex's Avatar
Join Date: Jun 2004
Location: Manchester
Posts: 4,504
Solex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond reputeSolex has a reputation beyond repute
Quote:
Originally Posted by cunning-stunt View Post
If I was wasn't thinking of doing a new Intel build soon, would it make any difference to hold off for a little while?
Yep 100%. Although it might be some time before the designs are changed such that the now lost performance is re-gained in new designs. Could be years.
Solex is offline  
 THE SOLEX 
Reply With Quote
Old 04-Jan-2018, 10:47   #38
EvilGrin
account shared with 10 people
EvilGrin's Avatar
Join Date: Oct 2003
Location: Lancs, UK.
Posts: 7,933
EvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond repute
Quote:
Originally Posted by Solex View Post
Yep 100%. Although it might be some time before the designs are changed such that the now lost performance is re-gained in new designs. Could be years.
https://www.kb.cert.org/vuls/id/584653

Quote:
Originally Posted by CERT
Solution

Replace CPU Hardware
.

__________________
Edugeek - Techies in Education!
EvilGrin is offline  
Send a message via ICQ to EvilGrin Send a message via AIM to EvilGrin Send a message via MSN to EvilGrin Send a message via Yahoo to EvilGrin  EvilGrinUK 
Reply With Quote
Old 04-Jan-2018, 14:53   #39
Lungboy
Roboplegic Wrongcock
Lungboy's Avatar
Join Date: Oct 2003
Posts: 15,248
Lungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond reputeLungboy has a reputation beyond repute
The Microsoft patch for Meltdown doesn't actually get turned on after being installed as it conflicts with lots of AV software causing bluescreens. AV companies need to alter registry entries before it can be turned on.
__________________
Please use my link for ordering Giffgaff simcards!
Lungboy is offline   Reply With Quote
Old 04-Jan-2018, 16:20   #40
EvilGrin
account shared with 10 people
EvilGrin's Avatar
Join Date: Oct 2003
Location: Lancs, UK.
Posts: 7,933
EvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond repute
It also needs to be specifically enabled on servers with reg keys.

https://support.microsoft.com/en-us/...ve-execution-s
__________________
Edugeek - Techies in Education!
EvilGrin is offline  
Send a message via ICQ to EvilGrin Send a message via AIM to EvilGrin Send a message via MSN to EvilGrin Send a message via Yahoo to EvilGrin  EvilGrinUK 
Reply With Quote
Old 04-Jan-2018, 23:11   #41
cunning-stunt
Falling to bits.
cunning-stunt's Avatar
Join Date: Oct 2003
Posts: 4,490
cunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond repute
Intel claims its new security updates make PCs ‘immune’ to Meltdown and Spectre CPU bugs

https://www.theverge.com/2018/1/4/16...mmune-response
cunning-stunt is offline   Reply With Quote
Old 05-Jan-2018, 00:10   #42
[n00b]Zippy
Waterborne Trailer-Trash
[n00b]Zippy's Avatar
Join Date: Oct 2003
Location: Shropshire Union Canal
Posts: 12,652
[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute[n00b]Zippy has a reputation beyond repute
Quote:
Originally Posted by cunning-stunt View Post
Intel claims its new security updates make PCs Ďimmuneí to Meltdown and Spectre CPU bugs

https://www.theverge.com/2018/1/4/16...mmune-response
You can exploit them with JavaScript? Without knowing much about it, that doesn't seem right?
__________________
And now we rise and we are everywhere
[n00b]Zippy is offline  
Send a message via MSN to [n00b]Zippy
Reply With Quote
Old 05-Jan-2018, 06:18   #43
cunning-stunt
Falling to bits.
cunning-stunt's Avatar
Join Date: Oct 2003
Posts: 4,490
cunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond reputecunning-stunt has a reputation beyond repute
Apple say all Mac devices hit by chip bug.

http://www.bbc.co.uk/news/technology-42575033
cunning-stunt is offline   Reply With Quote
Old 05-Jan-2018, 09:56   #44
NWA
Fish Schnapps
NWA's Avatar
Join Date: Oct 2003
Location: Harrow
Posts: 14,193
NWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond repute
Quote:
Originally Posted by [n00b]Zippy View Post
You can exploit them with JavaScript? Without knowing much about it, that doesn't seem right?
Any code that runs on a processor can theoretically be weaponised against this afaict. I suspect VBscript can do it too though there are probably much simpler ways.
__________________
Home is where the bandwidth is.

Quote:
Originally Posted by CryBaby
If Rooney kicks a ball at the World Cup then I will eat my underpants
NWA is online now  
Send a message via ICQ to NWA Send a message via MSN to NWA
Reply With Quote
Old 05-Jan-2018, 09:57   #45
Inertiaman
Join Date: Oct 2003
Posts: 38,772
Inertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond reputeInertiaman has a reputation beyond repute
But muh mac
__________________
Quote:
Originally Posted by Karmic
what you say doesn't count for shit because you rely on quotes from websites that are obviously biased
Inertiaman is offline  
Reply With Quote
Old 05-Jan-2018, 10:12   #46
EvilGrin
account shared with 10 people
EvilGrin's Avatar
Join Date: Oct 2003
Location: Lancs, UK.
Posts: 7,933
EvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond reputeEvilGrin has a reputation beyond repute
Quote:
Originally Posted by cunning-stunt View Post
Intel claims its new security updates make PCs ‘immune’ to Meltdown and Spectre CPU bugs

https://www.theverge.com/2018/1/4/16...mmune-response
Intel PR bullshit. You can be exploited just by viewing a web page. Mozilla has working Javascript exploits for both issues.

https://blog.mozilla.org/security/20...timing-attack/
__________________
Edugeek - Techies in Education!

Last edited by EvilGrin; 05-Jan-2018 at 10:16.
EvilGrin is offline  
Send a message via ICQ to EvilGrin Send a message via AIM to EvilGrin Send a message via MSN to EvilGrin Send a message via Yahoo to EvilGrin  EvilGrinUK 
Reply With Quote
Old 05-Jan-2018, 11:42   #47
NWA
Fish Schnapps
NWA's Avatar
Join Date: Oct 2003
Location: Harrow
Posts: 14,193
NWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond repute
https://video.twimg.com/tweet_video/DSp7SbVXcAAQ7FC.mp4
__________________
Home is where the bandwidth is.

Quote:
Originally Posted by CryBaby
If Rooney kicks a ball at the World Cup then I will eat my underpants
NWA is online now  
Send a message via ICQ to NWA Send a message via MSN to NWA
Reply With Quote
Old 08-Jan-2018, 14:24   #48
Lima Whisky
Always watching.
Lima Whisky's Avatar
Join Date: Oct 2003
Location: Mars
Posts: 423
Lima Whisky has disabled reputation
https://www.theregister.co.uk/2018/0...d_powered_pcs/

My aging Dell optiplex had a hissy fit this morning after today's critical update...

Amd athlon CPU ��
Lima Whisky is offline  
Send a message via ICQ to Lima Whisky
Reply With Quote
Old 08-Jan-2018, 15:24   #49
NWA
Fish Schnapps
NWA's Avatar
Join Date: Oct 2003
Location: Harrow
Posts: 14,193
NWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond repute
https://www.raspberrypi.org/blog/why...e-or-meltdown/

Excellent write up on how the bugs work (why Raspberry Pi isnt vulnerable is almost incidental) if you can spare 10-20 mins.
__________________
Home is where the bandwidth is.

Quote:
Originally Posted by CryBaby
If Rooney kicks a ball at the World Cup then I will eat my underpants

Last edited by NWA; 08-Jan-2018 at 15:34.
NWA is online now  
Send a message via ICQ to NWA Send a message via MSN to NWA
Reply With Quote
Old 08-Jan-2018, 15:29   #50
NWA
Fish Schnapps
NWA's Avatar
Join Date: Oct 2003
Location: Harrow
Posts: 14,193
NWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond repute
Quote:
Originally Posted by Lima Whisky View Post
https://www.theregister.co.uk/2018/0...d_powered_pcs/

My aging Dell optiplex had a hissy fit this morning after today's critical update...

Amd athlon CPU ��
https://www.theregister.co.uk/2018/0...d_powered_pcs/
__________________
Home is where the bandwidth is.

Quote:
Originally Posted by CryBaby
If Rooney kicks a ball at the World Cup then I will eat my underpants
NWA is online now  
Send a message via ICQ to NWA Send a message via MSN to NWA
Reply With Quote
Old 08-Jan-2018, 16:48   #51
PsYcHoKiLLa
topicophiliac
PsYcHoKiLLa's Avatar
Join Date: Oct 2003
Posts: 2,138
PsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond reputePsYcHoKiLLa has a reputation beyond repute
Rekt :/
__________________
Quote:
Originally Posted by Inertiaman View Post
Yes because after all it was absolute coincidence that he was shot right next to a handgun in a sock. Poor Duggan.

Dig the cunt up and shoot him again. Dickheads like him are why I can't buy a glock any more.
PsYcHoKiLLa is offline  
Reply With Quote
Old 08-Jan-2018, 18:26   #52
Ferg
Default Title Here
Join Date: Oct 2003
Posts: 1,879
Ferg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond reputeFerg has a reputation beyond repute
Quote:
Originally Posted by Scrobbs View Post
Another is 'cyber'. Death to all users of such.


Just seen this... my team name has "Cyber" in it!
Ferg is offline  
Reply With Quote
Old 09-Jan-2018, 11:13   #53
NWA
Fish Schnapps
NWA's Avatar
Join Date: Oct 2003
Location: Harrow
Posts: 14,193
NWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond reputeNWA has a reputation beyond repute
https://pdfs.semanticscholar.org/220...aaf7756857.pdf

Some granddads screaming I told you so at Intel. Quite brilliantly at least one author now appears to work for Google, this has been a long game for that man!*

*It may be in a completely unrelated area to the labs that did the work on the vuln
__________________
Home is where the bandwidth is.

Quote:
Originally Posted by CryBaby
If Rooney kicks a ball at the World Cup then I will eat my underpants

Last edited by NWA; 09-Jan-2018 at 11:16.
NWA is online now  
Send a message via ICQ to NWA Send a message via MSN to NWA
Reply With Quote
Reply

Go Back   trickery.net > Technical > Hardware


Similar Threads
Thread Thread Starter Forum Replies Last Post
Intel Desktop CPUs Price Cut Schedule assassin Hardware 0 19-Jan-2008 13:10
First Impressions Of The Demo? Mr_Skiff Real Time Strategy 21 24-Oct-2006 16:31
Intel May Acquire Graphics Chip Maker Nvidia assassin Hardware 2 05-Oct-2006 18:19
Advanced Micro Devices Sues Intel assassin Hardware 5 28-Jun-2005 22:30
Intel preps 1MB cache 130nm Pentium 4s Sc00ser Hardware 7 09-Nov-2003 00:21

Users Viewing Thread: 1 (0 members and 1 guests)
 

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 18:20.


Powered by vBulletin® Version 3.7.0 Release Candidate 3
Copyright ©2000 - 2018, Jelsoft Enterprises Ltd.
Copyright ©2003 - 2013, trickery.net