Showing posts with label Intel. Show all posts
Showing posts with label Intel. Show all posts

Sunday, 18 February 2018

Intel, Microsoft, Google Scramble for Solutions as Patches Slow Systems

Major tech companies, including Intel, Microsoft and Google, scrambled to calm the mood this week after a large number of computer users reported performance problems linked to security updates for the Spectre and Meltdown vulnerabilities.

A firestorm of criticism has erupted over the response to the chip flaws, which researchers at Google"s Project Zero discovered in 2016. Months passed before the problems were disclosed to the public. Further, the security patches released in recent days have been blamed for performance problems, including slowdowns in many systems. The fixes reportedly rendered a smaller number of systems unbootable.

Intel CEO Brian Krzanich on Thursday sent an open letter to the technology industry, pledging the company would make frequent updates and be more transparent about the process, and that it would report security issues to the public in a prompt manner.

Design Flaw


Intel Executive Vice President Navin Shenoy on Wednesday issued an update on the impact of the patches on performance, saying that eighth-generation Kaby Lake and Coffee Lake platforms would see less than a 6 percent performance decrease. However, users running Web applications with complex Javascript operations might see a 10 percent reduction.

The seventh-generation Kaby Lake platforms would experience a 7 percent reduction, and the impact on the sixth-generation Skylake platforms would be slightly higher at 8 percent.

Intel released numerous statements after the vulnerabilities were made public, and it shot down reports that its chips were the only ones at risk.

However, the Rosen Law Firm on Wednesday announced that it had filed a class action suit against Intel, alleging a failure to disclose the design flaw. The complaint cited reports that Intel had been warned of the problem. An Intel spokesperson was not immediately available to comment for this story.

Project Zero researchers discovered serious security flaws caused by "speculative execution," a technique used by modern CPUs to optimize performance, Matt Linton, senior security engineer at Google Cloud, and Matthew O"Connor, office of the CTO, wrote in an online post.

G Suite and Google Cloud platforms have been updated to protect against known attacks, the company said, though it acknowledged concerns that a variant of Spectre is considered more difficult to defend against.

Microsoft and others in the industry were notified of the issue several months ago under a nondisclosure agreement, Terry Myerson, executive vice president of Microsoft"s Windows and Devices group, noted earlier this week in an online post. The company immediately began engineering work on updates to mitigate the risk.

The flaw could allow a nonprivileged user to access passwords or secret keys on a computer or a multitenant cloud server, explained Stratechery analyst Ben Thompson in a post Myerson referenced.

Contrary to Intel"s protests, the potential risk from Meltdown is due to a design flaw, Thompson also noted.

Users of Windows 8 or Windows 7 systems using Haswell or older CPUs and would see a decrease in system performance after patching the flaw, Myerson noted.

Apple released updates for iOS, macOS High Sierra, and Safari on Sierra and El Capitan, noting the issue relates to all modern processors and affects nearly all computers and operating systems.

However there have been no reported compromises of customer data, Apple added, and Apple Watch is not affected by Meltdown or Spectre.

Performance Over Prudence


"The Meltdown and Spectre vulnerabilities require adjustment to critical, low-level interfaces in affected operating systems," said Mark Nunnikhoven, vice president of cloud security at Trend Micro.

"Given the scale of the issue, the patches by Microsoft, Apple, Google and others have been very successful," he told TechNewsWorld.

Still, there have been problems in some cases, Nunnikhoven said, noting that Microsoft and AMD have been pointing fingers at one another following reports of computers slowing down or in some cases not booting.

Microsoft has suspended automatic updates and is working with AMD on a solution, it said in a security bulletin.

Like most organizations, chip manufacturers long have prioritized speed over security," said Ryan Kalember, senior vice president of cybersecurity strategy at
Proofpoint, "and that has led to a tremendous amount of sensitive data being placed at risk of unauthorized access via Meltdown and Spectre.

The software patch required to fix Meltdown can slow computer processors down by as much as 30 percent, said Alton Kizziah, vice president of global managed services at
Kudelski Security.

"Organizations need to test patches before installing them to make sure that systems that may already be pushed to their limits won"t crash and cease functioning as a result of the patch," he told. Also, those using Microsoft patches may need to make adjustments to their registry keys to avoid interference with antivirus software.

Saturday, 20 January 2018

Intel Launches AMD Radeon-Powered CPUs

Intel took the wraps off its 8th Generation CPU core with AMD Radeon integrated graphics today. It’s a historical event for more than one reason. First, the new CPUs are likely to set a new high water mark for integrated graphics performance. Second, the new chips represent the first time AMD and Intel have ever collaborated in this type initiative. It’s a testament to how much the market has changed that this happened in the first place — even 10 years ago, the idea of an AMD-Intel alliance would’ve been unthinkable.

Intel is launching a suite of five new CPUs to introduce its new combined GPU+CPU core. All of these chips are Kaby Lake-derived, with four cores and eight threads.

Intel-CES-2

There are some really interesting takeaways in this chart. First, check out the ROP counts on the two Vega variants on display here. The i7-8809G and i7-8709G pack 1,536 GPU cores, clock speeds just a bit under 1.2GHz, and 64 ROPs. That’s a huge number of ROPs for an integrated core — significantly more, in fact, than AMD uses in its own Ryzen Mobile 2700U. As expected, overall memory bandwidth is above 200GB/s, which puts the chip in Polaris’ weight class in that regard.

The CPUs themselves are no slouch. The 3.1GHz base clock is relatively low, but boosting up to 4.1GHz should improve overall performance and most games don’t scale particularly well with higher CPU clocks.

Intel-CES-6

The GPU is attached to the CPU by an x8 PCIe 3.0 connection. Unlike the interposer technology that has made working with HBM and HBM2 difficult, Intel’s solution uses its own EMIB mounting technology that doesn’t require an interposer layer. The 4GB HBM2 stack (common to all of these chips) cuts power consumption by 80 percent compared with GDDR5.

Intel-CES-7

While they aren’t based on Coffee Lake, these new chips are still a big step forward for Intel. Integrating EMIB on consumer products, building a 24 CU GPU core with 1,536 GPU cores in total is a task Intel hasn’t taken on before. And these chips now support nine displays thanks to the combined Radeon+Intel graphics hardware. Intel is leaving its own graphics core enabled for consumers who want to use QuickSync or need to build a giant wall of monitors. As for performance, Intel’s numbers look extremely strong.

Intel-CES-4

Don’t just look at the bars — check what Intel is comparing against. The GTX 1060 Max-Q is a potent mobile GPU, but Intel claims the Vega GPU onboard its own NUC systems and in rigs coming from companies like HP and Dell can beat it.

Intel-CES-5

There are two flavors of Vega onboard these Intel chips. The GH (Graphics High) version beats out the GTX 1060 Max-Q, according to Intel. The GL (Graphics Low) version, meanwhile, is capable of taking on the GTX 1050.

These chips are a watershed moment, not just for Intel or AMD, but for the entire concept of integrated graphics. Ever since GPUs went on-die, we’ve seen two schools of thought emerge. One of them (generally favored by Intel) is that integrated graphics should still improve over time, but consumers won’t particularly favor it. Most people want inexpensive, acceptable graphics and don’t care if they get anything else. People who want higher-end solutions will buy them in the form of discrete GPUs.

The other argument, generally favored by AMD, is that putting higher-end graphics solutions into CPUs and focusing on improving performance over time will eventually make these chips appealing to segments of the market that would currently favor a discrete GPU. We haven’t really gotten to see this theory tested, however — AMD’s Bulldozer-derived APUs were so weak on the CPU front, they killed any chance of a reasonable market test.

If these chips prove popular with enthusiasts looking for a midrange, low-cost, fire-and-forget solution, it’ll say a great deal about what the market for these higher-TDP parts looks like and whether HBM2 can be a viable solution in this space. Expect Intel and AMD to keep a very close eye on how this pans out.

Wednesday, 10 January 2018

Intel Hit With Class Action Lawsuits Over "Meltdown" Security Flaw

The Spectre and Meltdown security stories were the major focus of the week. While both flaws are serious, Spectre hits everyone, while Intel is the company principally exposed by Meltdown. Meltdown is also the flaw associated with early reports of performance losses in some web servers and virtualization workloads, though it’s still not at all clear what kind of real-world penalties we should be expecting. Nevertheless, lawsuits are already starting to pile up, and there’s a lot of discussion over CEO Brian Krzanich’s recent stock sale.

Intel’s initial response to Meltdown was a masterful example of corporate doublespeak. It opens by noting Intel doesn’t believe the exploit can be used “to corrupt, modify, or delete data,” even though that’s literally not the problem being discussed. Meltdown allows data to be read out of kernel memory; it doesn’t let the attacker write it. Intel doesn’t distinguish between Meltdown and Spectre, and it name-checks AMD and ARM as a way of making the risk profile of the situation seem more evenly distributed than it appears to be. If Intel was hoping to avoid lawsuits, however, it hasn’t worked. As Gizmodo details, three separate class action suits have been filed against the company already.

ARM defines its own 3a variant of meltdown but doesn’t believe a software fix is required. Only the Cortex-A75 is affected by Meltdown (Variant 3).


What’s less clear is whether these lawsuits have any meaningful reason to exist. They’ve all been filed on behalf of consumers on the basis of lost performance, but we don’t have any information yet showing that consumer applications are impacted by Meltdown or Spectre. Until that’s proven, the lawsuit standing seems a tad weak.

Intel CEO Brian Krzanich’s actions, however, could still spell some trouble for the CPU giant. On October 30, months after being informed of the Meltdown and Spectre security flaws, Krzanich announced he would liquidate some 245,000 shares of Intel stock. He currently holds 250,000 shares, the minimum he’s required to hold as company CEO. All told, he sold $50 million worth of stock at the tail end of the year, just before news of these bugs began to break. The SEC could choose to investigate the situation — it launched an investigation of suspiciously timed stock sales in the Equifax breach this year — but no announcements have been made yet.

But while Intel’s handling of its PR response to this set of flaws deserves criticism, the security flaws themselves will be difficult to pin on negligence. Speculative processing and out-of-order execution have been critical components of high-end CPU performance for decades. Intel may be uniquely exposed to Meltdown, but Spectre hits everyone precisely because it weaponizes functional characteristics in a way that wasn’t done before. It’s hard to argue that a company was negligent in its designs when no one had previously identified an attack vector to protect against, or created even a proof-of-concept to expose the issue.

Sunday, 7 January 2018

Intel plans security updates for 90% of past 5 years" processors by end of next week

Following up on yesterday’s confirmation that security exploits can compromise computers with Intel processors, Intel today announced a timetable for updates to render recent computers “immune” to the exploits, now referred to as Spectre and Meltdown. It also provided some guidance on mitigation of the performance hits machines may take following the update.

On the consumer and enterprise side, Intel says that it has “already issued updates for the majority of processor products introduced within the past five years.” By the end of next week, it plans to have issued updates for more than 90 percent of the past five years’ processors.

Additionally, Intel notes that “many operating system vendors, public cloud service providers, device manufacturers and others have indicated that they already updated their products and services.” But no timetable was announced for patching Intel processors greater than five years old, though reports have suggested that up to 15 years of Intel processors may be affected.

Third-party benchmarking of the performance hits on affected machines ranged from 5-30 percent depending on the specific processor, OS, and task. Without offering details, Intel suggests that “the performance impact of [its] updates is highly workload-dependent and, for the average computer user, should not be significant and will be mitigated over time.” In cases where performance hits are higher, the company expects that future “improvement of the software updates should mitigate that impact.”

Thursday, 4 January 2018

Intel Claims Security Flaw Also Impacts Non-Intel Chips, Exploits Can"t Corrupt, Modify or Delete Data

Intel this afternoon addressed reports of a serious design flaw and security vulnerability in its CPUs, shedding additional light on the issue that was uncovered yesterday and has since received extensive media coverage.

In a statement on its website, Intel says that it planned to disclose the vulnerability next week when additional software patches were available, but was forced to make a statement today due to "inaccurate media reports."

According to Intel, the issue is not limited to Intel chips and the exploits in question do not have the potential to corrupt, modify, or delete data. Despite Intel"s statement, Intel chips are more heavily impacted, and it"s worth noting that Intel makes no mention of reading kernel level data.

Intel and other technology companies have been made aware of new security research describing software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from computing devices that are operating as designed. Intel believes these exploits do not have the potential to corrupt, modify or delete data.

Recent reports that these exploits are caused by a "bug" or a "flaw" and are unique to Intel products are incorrect. Based on the analysis to date, many types of computing devices -- with many different vendors" processors and operating systems -- are susceptible to these exploits.

Intel says it is working with several other technology companies including AMD, ARM, and operating system vendors to "develop an industry-wide approach" to resolve the problem "promptly and constructively."

As outlined yesterday, the design flaw appears to allow normal user programs to see some of the contents of the protected kernel memory, potentially giving hackers and malicious programs access to sensitive information like passwords, login keys, and more. Fixing the issue involves isolating the kernel"s memory from user processes using Kernel Page Table Isolation at the OS level.

Despite reports suggesting software fixes for the vulnerability could cause slowdowns of 5 to 30 percent on some machines, Intel claims performance impacts are workload-dependent and will not be noticeable to the average computer user.

Intel has begun providing software and firmware updates to mitigate these exploits. Contrary to some reports, any performance impacts are workload-dependent, and, for the average computer user, should not be significant and will be mitigated over time.

Intel goes on to say that it believes its products are "the most secure in the world" and that the current fixes in the works provide the "best possible security" for its customers. Intel recommends that users install operating system updates as soon as they are available.

For Mac users, Apple has already addressed the design flaw in macOS 10.13.2, which was released to the public on December 6.