AMD allegedly has Spectre-like security flaws

For discussions about security.
Post Reply
Message
Author
User avatar
6502coder
Posts: 677
Joined: Mon 23 Mar 2009, 18:07
Location: Western United States

AMD allegedly has Spectre-like security flaws

#1 Post by 6502coder »

https://www.cnet.com/news/amd-has-a-spe ... of-its-own/
"Researchers say they've found 13 flaws in AMD's Ryzen and EPYC chips, which could let attackers install malware on highly guarded parts of the processor."

musher0
Posts: 14629
Joined: Mon 05 Jan 2009, 00:54
Location: Gatineau (Qc), Canada

#2 Post by musher0 »

Hi 6502coder.

Yeah I saw that on the news too.

It is beginning to look like anthropologists need to study the mentality of the testers,
or of a sub-group of the IT class. This is not happening as randomly as it should,
therefore it becomes suspicious.

Or there is something in the air... Or planet Earth started picking up a new type of
rays when it turned back on its course last Dec. 21-22.

In any case, if you have a computer with an older CPU, news of this type certainly
cut short your desire to upgrade! I'm staying with my AMD Turion a while longer!

BFN.
musher0
~~~~~~~~~~
"You want it darker? We kill the flame." (L. Cohen)

User avatar
6502coder
Posts: 677
Joined: Mon 23 Mar 2009, 18:07
Location: Western United States

#3 Post by 6502coder »

In the interests of fair and balanced reporting, here's a quote from the following:

http://www.zdnet.com/article/linus-torv ... ity-report
Dan Guido, CEO of Trail of Bits, a security company with a proven track-record, tweeted: "Regardless of the hype around the release, the bugs are real, accurately described in their technical report (which is not public afaik), and [CTS Labs'] exploit code works." But, Guido also admitted, "Yes, all the flaws require admin [privileges] but all are flaws, not expected functionality."

It's that last part that ticks Torvalds off. The Linux creator agrees these are bugs, but all the hype annoys the heck out of him.

Are there bugs? Yes. Do they matter in the real world? No.

They require a system administrator to be almost criminally negligent to work.

Post Reply