Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shame Boy
Mar 2, 2010

CommunistPancake posted:

i'm hearing a lot of desktop users yelling about the 30% DROP IN SPEED for their VIDEO-GAMES

to me this looks like an issue that really doesn't affect desktop users, right? only situations where someone should be allowed to execute code but not read certain portions of memory (like virtualization)?

afaik it affects anything that does anything because the way they fix it is to make touching the kernel harder, and everything touches the kernel all the time

Adbot
ADBOT LOVES YOU

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


You Am I posted:

I'm looking at moving my IT career towards an IT Security role. Not sure where in IT Security to start from or with, any recommendations? Is it worth becoming an auditor or is there some other part of IT Security that's worth looking into?

Why do you want to move towards IT Security? What sort of skills do you currently have, and what sounds interesting? IT Security is a broad field so you're going to have to give us some more details. I've never done auditing as an actual job position, but it sounds awful to me at least. I'm sure some people enjoy that sort of thing.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate all the Oreos posted:

afaik it affects anything that does anything because the way they fix it is to make touching the kernel harder, and everything touches the kernel all the time
here's some company's benchmarks https://www.phoronix.com/scan.php?page=article&item=linux-415-x86pti&num=2

Last Chance
Dec 31, 2004

ate all the Oreos posted:

would you like to know something about it or did you just want to talk about it with yr yosbros

just wanted to shoot the poo poo

Last Chance
Dec 31, 2004

i think it could sink intel if its that bad

flakeloaf
Feb 26, 2003

Still better than android clock

rafikki posted:

Why do you want to move towards IT Security? What sort of skills do you currently have, and what sounds interesting? IT Security is a broad field so you're going to have to give us some more details. I've never done auditing as an actual job position, but it sounds awful to me at least. I'm sure some people enjoy that sort of thing.

Dunno if you can call it auditing but I spend a lot of my time compliance-checking a large userbase. They keep me busy, the excuses you hear are fantastic and there's basically nothing legal that isn't also sfw but good god am I glad to have something to do that isn't scrolling through endless reams of scan results. I like talking to big groups about social media secfucks and how not to get fired/charged, that's fun too.

Your iphone isn't a corporate asset, your dvd collection is not someone else's to back up for you and your rear end is not porn.

flakeloaf
Feb 26, 2003

Still better than android clock

Knowing nothing about cpu design how hard would this be to fix in future revisioh right 1166 isn't necessarily 1166

Shame Boy
Mar 2, 2010

Last Chance posted:

just wanted to shoot the poo poo

okay :hfive:

syscall girl
Nov 7, 2009

by FactsAreUseless
Fun Shoe

this is a thread for complaining about us politics, neh?

ate shit on live tv
Feb 15, 2004

by Azathoth

Subjunctive posted:

in April he told the SEC “I’m going to make this trade later this year”, and then it was on autopilot. he doesn’t get to change his mind. the optics are bad to people who think the CEO just logged into E-Trade to dump a few million in shares after getting an unpleasant email, but it’s super easy for the SEC to see whether the trade followed the 10b5-1 they have on file. I’m sure they did check when the form 4 came in, really, so I guess they did investigate a bit

I may be missing another angle though: what do you think they should do?

Investigate to see if the currently embargoed security vulnerability was known internally at the time. I honestly don't think he did anything illegal with his trade, but it would be nice if the SEC verified a bit.

ate shit on live tv
Feb 15, 2004

by Azathoth

quote:

Forcefully Unmap Complete Kernel With Interrupt Trampolines, aka FUCKWIT

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate poo poo on live tv posted:

Investigate to see if the currently embargoed security vulnerability was known internally at the time. I honestly don't think he did anything illegal with his trade, but it would be nice if the SEC verified a bit.
i have no idea how you people think the world works but it is absolutely not the sec's job to subpoena a ceo's emails every time they want to buy or sell stock in their own company

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?
How about only when those sales coincide with major happenings in that company?

Like making sure that, I don’t know, some securities weren’t, say, exchanged with foreknowledge gained from being inside?

That would be weird. It’d be like a commission about the exchanges of securities. We could call it the CES I guess.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Avenging_Mikon posted:

How about only when those sales coincide with major happenings in that company?

Like making sure that, I don’t know, some securities weren’t, say, exchanged with foreknowledge gained from being inside?

That would be weird. It’d be like a commission about the exchanges of securities. We could call it the CES I guess.
i mean, you could read the post on the previous page that explained that the ceo would have made their decision to sell their stock in april of last year, or you could continue to listen to el reg and reddit and hackernews with the rest of the internet, because why would the people on those websites lie to you?

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

anthonypants posted:

i mean, you could read the post on the previous page that explained that the ceo would have made their decision to sell their stock in april of last year, or you could continue to listen to el reg and reddit and hackernews with the rest of the internet, because why would the people on those websites lie to you?

The point that was being made was did he know about the issue back in April. Apparently you’re just in such a rush to poo poo on people you just poo poo your pants instead.


ate poo poo on live tv posted:

Investigate to see if the currently embargoed security vulnerability was known internally at the time. I honestly don't think he did anything illegal with his trade, but it would be nice if the SEC verified a bit.

See? Odds are that nothing wrong happened, but it’d be a good thing to investigate as it is actually their job to double-check things like that.

ohgodwhat
Aug 6, 2005

Like, the SEC doesn't have the resources to investigate much more clear cut cases of insider trading like Kraft and 3G partners or whatever but sure let's have them instead investigate when every piece of material news was known internally just in case some C level happened to have a 405 in to sell. I mean, there aren't that many cases of news coming out that affects stock prices, nor do executives sell stock very frequently.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Avenging_Mikon posted:

See? Odds are that nothing wrong happened, but it’d be a good thing to investigate as it is actually their job to double-check things like that.

anthonypants posted:

i have no idea how you people think the world works but it is absolutely not the sec's job to subpoena a ceo's emails every time they want to buy or sell stock in their own company

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

ohgodwhat posted:

Like, the SEC doesn't have the resources to investigate much more clear cut cases of insider trading like Kraft and 3G partners or whatever but sure let's have them instead investigate when every piece of material news was known internally just in case some C level happened to have a 405 in to sell. I mean, there aren't that many cases of news coming out that affects stock prices, nor do executives sell stock very frequently.

Right, I keep forgetting that America is ultra-turbo-hosed, as opposed to the turbo-hosed it was previously. Y’all should move to Canada. We’re legalizing weed nationwide.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Avenging_Mikon posted:

Right, I keep forgetting that America is ultra-turbo-hosed, as opposed to the turbo-hosed it was previously. Y’all should move to Canada. We’re legalizing weed nationwide.

Lol that you appear unaware of how Canada has relatively lax financial crimes enforcement

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
i would venture that most democracies are bad at investigating and punishing crimes of people with money, because if they were good at it the people with money would lobby to make them bad

cinci zoo sniper
Mar 15, 2013




ate all the Oreos posted:

afaik it affects anything that does anything because the way they fix it is to make touching the kernel harder, and everything touches the kernel all the time

no one games on linux or windows servers, all the crying is baseless

minato
Jun 7, 2004

cutty cain't hang, say 7-up.
Taco Defender
gamers saw "speculative execution" and thought it was about blind-firing from cover

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

cinci zoo sniper posted:

no one games on linux or windows servers, all the crying is baseless
i've already seen at least one article that says there's performance issues on windows because of this thing

cinci zoo sniper
Mar 15, 2013




anthonypants posted:

i've already seen at least one article that says there's performance issues on windows because of this thing

itll be very microsoft for virtualisation security issue to affect windows 10 home. also what articles are you seeing with embargo still up?

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

cinci zoo sniper posted:

itll be very microsoft for virtualisation security issue to affect windows 10 home. also what articles are you seeing with embargo still up?

stuff that lets you leak memory from other vms on the same host also lets you leak memory from just other stuff on your machine, not sure why you'd think that's unusual.

there aren't any articles really, people are just reading between the lines.

cinci zoo sniper
Mar 15, 2013




Jabor posted:

stuff that lets you leak memory from other vms on the same host also lets you leak memory from just other stuff on your machine, not sure why you'd think that's unusual.

so whom are you leaking your memory to on a local machine? or is it non-vm apps that are leaking?

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

cinci zoo sniper posted:

so whom are you leaking your memory to on a local machine? or is it non-vm apps that are leaking?

are you one of those templeos proponents who doesn't believe in process isolation or something?

cinci zoo sniper
Mar 15, 2013




Jabor posted:

are you one of those templeos proponents who doesn't believe in process isolation or something?

no, i am not

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
then maybe you can figure out on your own why leaking kernel memory to a user-space process is a bad thing

cinci zoo sniper
Mar 15, 2013




Jabor posted:

then maybe you can figure out on your own why leaking kernel memory to a user-space process is a bad thing

that would require an understanding of low level stuff

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
were you looking for a tweet of someone saying "thing bad" in 140 characters or less?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


sounds like we picked an excellent time to try and move to virtual desktops at work lmao

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.

cinci zoo sniper posted:

that would require an understanding of low level stuff

"anything is root without the patch that can make things significantly slower"

cinci zoo sniper
Mar 15, 2013




Jabor posted:

were you looking for a tweet of someone saying "thing bad" in 140 characters or less?

no, im basically waiting for an embargo to lift and deets to come in so i can make a meaningful q on the subject. there's too much seeming hysteria everywhere to buy a "thing bad", especially in 140 characters or less

atomicthumbs posted:

"anything is root without the patch that can make things significantly slower"

that's less than great

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
This will most certainly affect client machines too, as there are low level software features that take advantage of this feature, and could cause kernel dumps that could compromise user systems easily.

Its most certainly going to be an issue. Its not like Windows Server and Windows are very different or do very different things, they both function using the same kernel.

Cybernetic Vermin
Apr 18, 2005

otoh i suspect that the performance impact will be reasonably modest for consumer workloads, it makes decent sense that e.g. database workloads would be sensitive, but i struggle to think of a consumer workload that'll load the syscalls/sec down very hard. for games for example a modern graphics driver should not have to cross the boundary very often, they have to be doing a lot of bulking in userspace to make it work even with the normal lower performance impact

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Cybernetic Vermin posted:

otoh i suspect that the performance impact will be reasonably modest for consumer workloads, it makes decent sense that e.g. database workloads would be sensitive, but i struggle to think of a consumer workload that'll load the syscalls/sec down very hard. for games for example a modern graphics driver should not have to cross the boundary very often, they have to be doing a lot of bulking in userspace to make it work even with the normal lower performance impact

Graphics loads, no, but most gameplay is still CPU intensive to handle in game engine mechanics and everything else. It'll still have an impact, what impact that is I can't say yet, but I suspect it will at least take a hit.

Most modern games still don't take advantage of multi-core processing, and are heavily single core dependent and that's likely to allow the microcode change to have a performance hit.

Cybernetic Vermin
Apr 18, 2005

CommieGIR posted:

Graphics loads, no, but most gameplay is still CPU intensive to handle in game engine mechanics and everything else. It'll still have an impact, what impact that is I can't say yet, but I suspect it will at least take a hit.

Most modern games still don't take advantage of multi-core processing, and are heavily single core dependent and that's likely to allow the microcode change to have a performance hit.

if the details we have so far are correct there will be almost no impact on "pure" cpu-intensive loads, since the fix so far suggested is a huge overhead on syscalls as the entire kernel pagetable needs to be established on entry and then fully discarded on exit. if there is a microcode fix it may indeed have some impact, but we have no idea what that would look like in that case. since games mostly avoid doing io during gameplay (and to the extent they do it is large streaming chunks), and graphics drivers bulk calls in userspace, most games should be fine, they just don't syscall much

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Cybernetic Vermin posted:

if the details we have so far are correct there will be almost no impact on "pure" cpu-intensive loads, since the fix so far suggested is a huge overhead on syscalls as the entire kernel pagetable needs to be established on entry and then fully discarded on exit. if there is a microcode fix it may indeed have some impact, but we have no idea what that would look like in that case. since games mostly avoid doing io during gameplay (and to the extent they do it is large streaming chunks), and graphics drivers bulk calls in userspace, most games should be fine, they just don't syscall much

Fair enough, and to support your claim, I did find this:

https://www.phoronix.com/scan.php?page=news_item&px=x86-PTI-Initial-Gaming-Tests

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



start of a thread:
https://twitter.com/lavados/status/948536300830851072

e: just to be clear i do think there's a ton of hysteria for what is rowhammer again

  • Locked thread