News has just started spreading that researchers have sighted another eight Spectre like vulnerabilities in Intel processors, all resemble Spectre, four of them are critical. The new vulnerabilities are grouped and named as Spectre-ng. The newly discovered vulnerabilities would make it really easy to exploit a host from a simple VM.
German c't / Heise reports and breaks the news today, as the new vulnerabilities have not been made public just yet. There would be 'no doubt' that these are real vulnerabilities. While technical details are missing, the attack scenarios resemble close to what the Spectre vulnerabilities are.
Currently, most at risk are shared hosting providers, once you have access to your rented server-container, you could exploit the processor to retrieve secure data. All eight vulnerabilities share the same design problem that the "Meltdown and Spectre" vulnerabilities detailed as well - they are, so to speak, Spectre Next Generation ergo Spectre NG. c't mentions they have concrete information about Intel's processors and their patch plans. However, there are some indications that other processors are affected as well, at least some ARM CPUs are also vulnerable to some extent. Further research into whether and to what extent the AMD processor architecture is vulnerable at (if at all), is not yet known.
Intel is reportedly actively and nervously working on Spectre NG patches behind the scenes; other patches are developed in collaboration with the operating system manufacturers (Microsoft / Linux etc). When exactly the first Spectre NG patches and firmware updates will become available is not yet clear. According to information, Intel is planning at least two patch waves: a first one should start in May; a second is currently scheduled for August. For at least one of the Specter NG patches is already a specific date as it was Google's Project Zero that has found one of the vulnerabilities, on May 7 - the day before the Windows Patchday - the 90-day warning period expires. So it's likely that when the first patch would be released for Microsoft Windows. Microsoft is preparing CPU patches: they appear to be in the form of optional Windows updates, and not so much microcode updated (firmware). The PC motherboard and server manufacturers probably need too long for BIOS updates.
Intel classifies four of the Specter NG vulnerabilities as "high-risk"; which in Intel language is translated as: super dangerous. The danger of the other four is rated as medium. According to c't/Heise, Specter-NG risks and attack scenarios are similar to those of Specter - with one exception. C't calls the Intel vulnerabilities and their procs a Swiss Cheese due to the many security holes.
Does it matter when 99% of regular computer users are running crapware? Does it matter when phones are running google os, soon fuschia, on arm? IT DOESN'T MATTER to them the very few people who care are not important, times when minority could change anything are long gone, at least two thousand years
Noah Phillips
it matters when the jews start having data leaked and loose money.
Things like this is the reason why I have to disable Javascript and shit ton of other Web technologies. I will buy the RPI 4 when it comes out and replace my current computer with it.
I wonder if Intel's been sneaking these in on purpose to make it easy to assault VM farms?
Angel Moore
It's weird because I actually used an Osborne 1 in the early 80's, and don't remember that elephant book. Instead it had a couple binders, and the pages were printed on cardstock. Pretty fucking high quality stuff, and never saw anything like it again. Even my Amstrad CPC's manual was just regular paper in a ring-bound manual. Same with Amiga 500. Oh, and those Osborne books had everything from learning to get around in the shell and batch programming, using Wordstar and Supercalc, all the way to BASIC and assembly language programming (including explanation of all opcodes, memory layout, etc.)
Connor Morgan
fuggin checked
Ryder Smith
tfw your PSP is faster than that computer
Jace Hill
Has anyone got HDMI, X-windows working on it yet?
Jackson Hernandez
How could a processor be this bad? No wonder there's so many update on linux kernel lately.
Why are grayhats not using these against elite pizzahosts? I cant believe such small sites like pingpong pizza and dr.pong are on dedicated server hosts just for their masonic cabal cannibals.
Most microcontrollers are faster than that computer.
Samuel Hughes
Implying these aren't extremely clever backdoors which have enabled the gathering of countless petabytes of intelligence.
Aiden Taylor
Step one: Step two:
Joseph Thompson
That is, my PSP inside of my Ryzen.
Liam Reed
Also you have to refuse to use any machines that run 3rd party binaries on the same machines as have your data. So no cloud for you (unless it's already encrypted - then it's not as big of a deal, but they could still possibly find out file dates, which could be used for intimidation purposes).
Ethan Ramirez
sister thread: >>>Zig Forums11552103
Justin Barnes
5 bucks says if AMD gains the upper hand, they will pull a Jewtel and jack up their prices to the sky. Do you honestly expect AMD to be any different from Jewtel?
Jordan Green
I'm completely fine with them commanding a market price for their products, even if this means having it jacked up skywards because there's no competition. As long as they don't engage in Intelaviv-style jewry like artificial limitations on processors' instruction set extensions, needlessly breaking mobo compatibility or locking clocks on all but the highest-end "unlocked" premium processor model.
>Using (((cloud))) in any form other than remote disk for locally mounted encrypted partition in current year We facebook now, yay! I fucking love technology!
Matthew Price
Technologe loves you too up your ass.
Gabriel Walker
no. I don't believe AMD is inherently better than Intel, but a balance must be maintained to keep them in check. Right now, the balance has been lost.
Intel said they'd have a fix by this week at first, but it turns out it's been delayed for at least another two weeks.
Intel's such a hot mess. Sell your stock now!
James Foster
Not a waste of quads for once.
Jordan Watson
Neon Genesis.
Dylan Lewis
I want to fug amada
Noah Howard
Did Intel finally get around to fixing Spectre yet?
Henry Perry
Intel is for faggots OwO
Angel Wilson
...
Nathaniel Nguyen
So is Incel going to fix any of these issues or are they baked too deep into the hardware?
Christopher Miller
What the fuck?
Jaxson Reyes
Welp time to haul out the old G5 Powermac.
Nicholas Jackson
It's shit's a backdoor. The NSA is probably having a funeral for one of their favorites, but don't worry, there are many others.
James Martin
Going to order a Talos II Lite soon, screw Incel.
James Myers
...
Hunter Lee
The POWER Macs were shown to be vulnerable to Specter-class vulns as well.
Juan Williams
Still botnet.
Dominic Collins
Still retarded so I can make cute assertions too
Josiah Martin
Yeah but yours aren't based on any facts, unlike his. Because you're a fucking Intel shill.
Julian Carter
What are SMM and PSP?
Kayden Johnson
Can someone design a modernish libre CPU and get Zeloof to make it already, I'm sick of this crap
Jason Butler
PSP is based on ARM TrustZone and has nothing to do with x86-64 itself. Stay a LARPNigger
Kayden Edwards
You're a massively salty shill. The PSP is located in every AMD processor since 2012. x86 cuckolds are so fucking weak that they let other processor archetechtures into their own processors. Not to mention that x86 is bloated to shit with old instructions from the 8086 that don't even function properly (like AAA) and Intel is forced to keep their bugs to maintain compatablitly.
ARM is shit AMD is better for x86 and is still inferior to ARM
Kayden Morris
...
Brandon Howard
Hello Zig Forums my name is Shlo...err...Jerry and I'm here to give you tech tips how to secure your Intel box! Unplug the network cable. What's that, your box is a notebook? Open 'er up and disconnect the WiFi antenna from the mainboard! Easy as taking a shekel from a newborn jew! What's that, your box is a server? I don't see the problem in this case. Servers are meant to serve information are they not? In fact your purpose is to serve a higher purpose, goy. Shek ke ke ke ke ke!
Jack Roberts
Weak copypasta. Make it a bit more subversive will ya?
Isaac Sanchez
Don't put a punchline six words into the joke, retard
Kevin Nelson
Hahahaha Intel shill's latest tack. What a bunch of failures.