[DISCUSSION] Meltdown and Spectre

Discussion in 'PC Hardware' started by scaramonga, Jan 3, 2018.

  1. Enthousiast

    Enthousiast MDL Tester

    Oct 30, 2009
    47,292
    94,815
    450
  2. Michaela Joy

    Michaela Joy MDL Crazy Lady

    Jul 26, 2012
    4,071
    4,651
    150
    @Enth: You're right....

    But that girl can sure cook. :D
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. Joe C

    Joe C MDL Guru

    Jan 12, 2012
    3,522
    2,093
    120
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. markokk888

    markokk888 MDL Senior Member

    Aug 13, 2012
    292
    67
    10
    Is a manufacture of a motherboard have to release compatible bios update to somehow inject or support/update the new microcode of a cpu or is it possible to do this directly without updating the bios ?
    i'm a little confused of what steps should i take because i have a processor that have a new microcode update available but the manufacturer of the motherboard don't have new bios updates or a any solution to this problem they basically don't release a s**t since 2015. i have Intel Core i5 4460 and MSI NIGHTBLADE B85C motherboard and i'm affected by a Spectre vulnerability.
    what i can do ?
     
  5. John Sutherland

    John Sutherland MDL Addicted

    Oct 15, 2014
    867
    1,388
    30
    #348 John Sutherland, Apr 18, 2018
    Last edited: Apr 19, 2018
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. markokk888

    markokk888 MDL Senior Member

    Aug 13, 2012
    292
    67
    10
    Well, good to know thanks for the info :)
     
  7. toyo

    toyo MDL Senior Member

    Aug 14, 2009
    472
    313
    10
    What is different if you are using a BIOS update "instead"? I'm not sure this is the correct term.

    What I am sure, however, is that:

    - Intel released that first round of 'buggy" microcode updates that they recommended are no longer used; this BIOS was actually stable on Coffee Lake, I think only older platforms had issues, so I kept it
    - then Microsoft made available KB4090007 with new, functional microcode

    At this point, I was curious how this would affect my PC (8700k), so i installed that update. There was a pretty clear impact in performance, for example in Cinebench and a few AIDA64 tests. I uninstalled it immediately.

    - MSI released a new BIOS containing the same microcode basically; updated my BIOS, there's no additional performance hit and AIDA64 tests were similar to previous BIOS.

    So, somehow, installing the microcode from the Microsoft patch instead of a BIOS flash resulted in a performance hit. Is there a significant difference between the 2?

    Thanks.
     
  8. dhjohns

    dhjohns MDL Guru

    Sep 5, 2013
    3,262
    1,731
    120
    I tell you what. How many years has this code gone unnoticed? How many years have we lived with it unknowing, and been fine? I am passing on any patch, especially one that slows down my computer. Remember the old adage If it ain't broke don't fix it, also if it is in print, that doesn't make it true, and I certainly don't have to respond to mass hysteria over a problem that has never, ever once effected me or anyone else.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. Yen

    Yen Admin
    Staff Member

    May 6, 2007
    13,081
    13,980
    340
    #352 Yen, Apr 19, 2018
    Last edited: Apr 19, 2018
    There must be a difference...and the difference is that the M$ patch is not a MC update alone.
    From the technical aspect it does not matter whether the (same) MC come from BIOS or from the OS...

    You find the hint at their wording :"This update includes microcode updates from Intel for the following CPUs.."

    The update includes MC updates besides of other unknown stuff...it is no pure MC update.

    You do not consider that the situation has changed by publishing the vulnerabilities....
    If somebody discovers a vulnerability then the one is always in a dilemma.
    When publishing it then the public knows about...from that time the vulnerability exists (to the public) not before!
    And by that the need to patch them....since a known vulnerability can be exploited.

    It depends on the CPU type/architecture.

    In this regard one might inform about RISC / CISC approach.....

    One of Intels 'faults' that time had been to go for CISC (until 80386)....we here for scientific use (NMR) could not use any Intel CPU in the early 90s.....we had to go for alpha RISC to live calculate a furrier transformation.....

    To eliminate the performance gap to RISC they came to 'strange' ideas...
    AFAIK the 80486 then had got some 'attributes' of RISC...

    Intel actually never had a right intuition when it came to CPU development, in this regard they are similar to M$ and only their strong alliance and unfair market politics could make them persist..just remember the threats to mainboard manufacturers against AMD mainboards...
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. toyo

    toyo MDL Senior Member

    Aug 14, 2009
    472
    313
    10
    Yeah it's probably impossible to tell what exactly is in both the Microsoft KB update and the new BIOS.
    What I do know is that before them, CPU-Z would say that I am vulnerable to Spectre (web page from validating CPU). After both updates, it says:
    Rev. 0x84 ► Spectre (CVE-2017-5715) Patched ◄
    So the microcode revision from the new BIOS is the same as the one in the KB. But there's no performance hit (compared to previous microcode BIOS update, cause against unpatched there's obviously a performance difference). The Inspectre tool would not say the PC is vulnerable with the first microcode, it would consider it properly patched, it's just CPU-Z that insists on the latest microcode.

    Now about if it's worth it or not to patch these vulnerabilities. The Spring Creators Update has the patches built in it. It seems like you can still disable the protections from Inspectre, but I doubt many will. While I don't have critical info to guard, i would still not like it having to change passwords and recover accounts cause my PC got hacked or having it used in some botnet for whatever the hackers feel like. This makes me wonder, let's say one would not apply these protections, but uses a good internet security suite, like Kaspersky's. Would it matter? Or it would be irrelevant.
     
  11. Yen

    Yen Admin
    Staff Member

    May 6, 2007
    13,081
    13,980
    340
    One should not forget that such check tools like Inspectre tool are from pure scientific view not able to tell something about the condition "your PC is still vulnerable to.../ is not vulnerable anymore"
    Why?
    Quite easy..the check tools come along with the self-determined idea WHEN the vulnerabilities have been patched....

    That is a good question....
    We can only talk about probabilities....and it depends on use.
    I think when using 2FA on sensitive accounts (banking etc) they should be safe.

    One should know what the exploits can....they can read arbitrary memory....(RAM)....

    I have an unpatched w7 and Linux mint dual boot. Linux is fully patched, windows not at all....I do my banking on Linux, though...
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  12. Michaela Joy

    Michaela Joy MDL Crazy Lady

    Jul 26, 2012
    4,071
    4,651
    150
    TBH, I'm still not convinced that this isn't some kind of ploy to make people update to newer hardware. And I'm not going to patch my CPU and make it a cripple because of
    this nonsense.

    I bought an I7. Not a P4 or an I3.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  13. nodnar

    nodnar MDL Expert

    Oct 15, 2011
    1,315
    1,040
    60
    #356 nodnar, Apr 19, 2018
    Last edited: Apr 19, 2018
    That was my first reaction too.. [#16] And I keep wondering why people in the ict security business have to reveal such vulnerabilities every time.. It feels a bit like ;`look, ma how smart I am..` While it is not that smart at all, crooks are unlikely to invent the wheel every time;in any case they did not for nearly two decades..But it looks like Intel cs really messed it up this time...all in the name of speed. And they are unlikely to introduce better processors anytime soon...So, if all the crooks jump on the meltdown/spectre bandwagon, we may have to resort to a raspberry to do our online banking business..;)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  14. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,575
    15,646
    270
    Exactly. The bad guys didn't know about Meltdown and Spectre, now they KNOW. Scary! But not that scary to me lol, cause:
    Me too, buddy, me too.
     
  15. Joe C

    Joe C MDL Guru

    Jan 12, 2012
    3,522
    2,093
    120
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. Joe C

    Joe C MDL Guru

    Jan 12, 2012
    3,522
    2,093
    120
    Google found this flaw and told Intel and AMD about this issue 6 months before they made it public, If Intel and AMD sat on their butts and did nothing, then I can not blame Google for making it public
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  17. 2cmp

    2cmp MDL Junior Member

    Apr 2, 2018
    66
    34
    0
    #360 2cmp, Apr 19, 2018
    Last edited: Apr 19, 2018