I’ve been seeing more stuff come in about more and more chip level vulnerabilities and it has bothered me enough that I feel like I need to get on my soapbox for a minute…

Any VMM level mitigation, especially disabling hyperthreading which is what they are implying in the last paragraph will cause serious performance degradation. The real solution is to patch the hypervisor to prevent code execution in the first place while the overall situation can be assessed. The issue is that any higher level patch doesn’t actually eliminate the flaw, it just prevents its exploitation, and all it takes is a clever person enough time and motivation to sidestep any countermeasures.

From my perspective, they are just defining another specific instance of a universal truth of predictive memory management, which is that it’s exploitable, it’s a byproduct of its function.

The real issue is we’ve become reliant on that type of memory management and expect it in our performance metrics.. Unless we come up with an entirely new way to manage memory, there are two options;

Accept these fundamental issues with predictive memory management and demand software vendors become more nimble to patch zero-day for exploits of the vulnerabilities OR completely give up on predictive memory management and accept that we are nearing the physical limits in performance of the materials we use to manufacture silicon and that any attempt to increase performance by ‘fudging’ performance using a predictive algorithm will create an unacceptable security threat vector…

Everyone is talking about these things from a ‘What are we going to do about this’ perspective, but the truth is, there really isn’t anything that can be done until the more basic underlayers are communally understood….

  

I’m done…

0
0
0
s2sdefault