Announcement

Collapse
No announcement yet.

Linus Torvalds Comments On STIBP & He's Not Happy - STIBP Default Will End Up Changing

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #51
    Originally posted by ALRBP View Post
    We talked a lot about Spectre, Meltdown or Heartbleed but, AFAIK, they were never actually exploited in practice
    And you know that because no data thief bragged in public "Har har, I stole all your valuable credentials/bitcoin/whatever by exploiting Spectre!"...?
    The very important difference with Spectre and Meltdown is that especially on the currently so fancied rented "cloud" computer instances, you can steal data from VMs sharing the same physical host, without leaving any evidence that the victim could see.

    Unlike Trojans/Viruses or exploits of network protocol interfaces, the attacker does not need to change any byte on the victims (virtual) machine, he does not need to rely on any specific software bug on the attacked system, and there won't be any log entries or such providing evidence of intrusion to the victim.

    Much unlike you, I am pretty convinced that Spectre and especially Meltdown have been exploited, big time. Whether the attackers already evaluated and made use of or money from the data they extracted from victim systems - well, maybe not yet. Will they tell the victims how they got to their data? Certainly not. Will Cloud providers admit such attacks were executed? Of course not, why would they?

    Your arguments towards not fixing security bugs for the sake of performance are convincing only for single-player, non-networked gaming machines. And that is not the predominant domain of Linux as an operating system.

    Comment


    • #52
      Originally posted by Weasel View Post
      Why don't you just underclock your CPU to 1 Mhz, and remove all out-of-order execution, that will easily give you a massive security boost. I mean, who cares about performance would surely clock it back on! HA HA HA!

      Performance > Security. Within limits obviously. Nobody fucking buys a new CPU for security and I sure don't want opinionated people like yourself to ruin the performance I PAID FOR.
      I would agree with overclocker on this one, better to be safe than sorry. That's my view, but then again it should be easy to compile your own kernel without the safety precautions, if you want speed. It's like not using a condom when having sex, if it's your regular partner (male or female or whatever) then you are probably safe, but new partner, not tested for STD'S, it can really ruin you life...

      This thread is really full of unfriendly comments all over the place. This was not intended as such.

      Kind regards
      Brut.
      Last edited by Brutalix; 19 November 2018, 06:18 PM.

      Comment


      • #53
        That remember me of ext4 nobarrier by default... long time ago

        Comment


        • #54
          Originally posted by Weasel View Post
          Why don't you just underclock your CPU to 1 Mhz, and remove all out-of-order execution, that will easily give you a massive security boost. I mean, who cares about performance would surely clock it back on! HA HA HA!
          MOS Technology 6502.

          Oh wait, the jam exploit...

          Originally posted by carewolf View Post
          non-moderated Linus
          Who is moderating him?

          Comment


          • #55
            Originally posted by birdie View Post

            "hostilely" - you mean I call BS what I see BS? Sorry, I can't restrain myself when there is a lot more idiots on the Internet than of reasonable people who actually know something. You see, IRL idiots are at least prudent enough to remain silent - not so much on the internet where absolute most people are hidden behind nicknames. And, also when you're polite, your reasoning will be simply dismissed.

            Opinionated, you mean "knowledgeable"?

            "ironically, attention-seeking" - never thought about that actually. And if I really were, I'd find another avenue. And being notorious among Linux users? WTF, are you even serious? It's like being famous among hobos. Yes, it's a sort of insult but your reply was a pure insult in the first place because it egregiously misrepresented facts.

            Still, fuck off. At least I made Linux notice the issue. You, petty fuckers at Phoronix, may keep on upvoting your insults towards me as much as you want. Most of you bloody suckers haven't done anything for Linux or open source in your entire useless life and you hate everyone with a brain who notices issues with your OS which most people in the world couldn't care less about.


            Well, thank you.
            Thank you for writing in small font that is almost the same colour as the text box. It really makes what you're writing easy and understandable to read.

            Comment


            • #56
              Michael Thanks for article! Just reverted that patch in our kernel source tree.
              birdie Good Job!

              Comment


              • #57
                Originally posted by Weasel View Post
                It's not about hate. What I truly despise (and maybe birdie as well) is people spreading nonsense (to put it nicely) and refusing to accept facts, and there's no shortage of them on this forum.
                Treat people how you want to be treated, it's as simple as that.

                Comment


                • #58
                  Originally posted by Jabberwocky View Post

                  Treat people how you want to be treated, it's as simple as that.
                  Well I'm not sure about that, I wouldn't want a masochist to believe that way while interacting with me.

                  Comment


                  • #59
                    Originally posted by birdie View Post
                    Michael and it's me, sir, who made Linus notice the issue. I'm just saying. Despite tons of hatred that I receive here. Luckily I don't care.

                    It's kinda sad that when I'm saying something here people disregard me, but if it's Linus then, "Oh, God, he's so right".
                    Irrespective of your biases, you did good here. We all thank you. Now we're gonna get sane behavior out of this.

                    Also Thanks needs to go to Michael as well, I mean he develops PTS, and it was his time and equipment and tools that highlighted this. I legitimately feel like Michael deserves to get paid for this. His tools and collection of equipment for highlighting performance regressions is amazing.

                    Comment


                    • #60
                      Originally posted by aufkrawall View Post
                      I'm not yet in a phase of life where I can support every project I like monetarily.
                      I regularly click some ads though.
                      FYI, don't click ads, just letting them display on your screen is enough for Michael to get paid.

                      Comment

                      Working...
                      X