Intel's 8th-Gen Xeon and Core Processors Feature Redesigned Hardware to Address Spectre and Meltdown Vulnerabilities

Discussion in ' News Discussion' started by MacRumors, Mar 15, 2018.

  1. MacRumors macrumors bot


    Apr 12, 2001

    Intel CEO Brian Krzanich today announced that its next-generation Xeon Scalable (Cascade Lake) processors and its 8th-generation Intel Core processors will feature redesigned components to protect against the Spectre and Meltdown vulnerabilities that affect all modern processors.

    Spectre variant 1 of the vulnerabilities will continue to be addressed in software, while Intel is implementing hardware-based design changes to offer future protection against Spectre variant 2 and Meltdown variant 3.

    Intel's new Xeon Scalable processors and its 8th-generation Intel Core processors are expected to start shipping out to manufacturers in the second half of 2018.

    Ahead of the hardware changes, Intel says that software-based microcode updates have now been issued for 100 percent of Intel products launched in the past five years, and all customers should make sure to continue to keep their systems up-to-date with software updates.

    Krzanich also reaffirmed Intel's commitment to customer-first urgency, transparent and timely communications, and ongoing security reassurance.

    Apple began addressing the Meltdown and Spectre vulnerabilities back in early January with the release of iOS 11.2, macOS 10.13.2, and tvOS 11.2, which introduced mitigations for Meltdown. Subsequent iOS 11.2.2 and macOS High Sierra 10.13.2 Supplemental updates introduced mitigations for Spectre, as did patches for both macOS Sierra and OS X El Capitan in older machines.

    Apple's software mitigations for the vulnerabilities have not resulted in any significant measurable decline in performance.

    Article Link: Intel's 8th-Gen Xeon and Core Processors Feature Redesigned Hardware to Address Spectre and Meltdown Vulnerabilities
  2. robotica macrumors 6502a


    Jul 10, 2007
    I was going to buy a new MacBook in January until all this came to light.

    Can’t wait for new MacBooks now!
  3. Saipher macrumors demi-god


    Oct 25, 2014
    Wait, Idk there were different Meltdown and Spectre variants.

    I guess I'll wait until 2019 to get a new Mac.
  4. gnasher729 macrumors P6


    Nov 25, 2005
    Linus Torvalds seems to have got early design specs, and he was let's say deeply unimpressed.

    It seems that Intel's new chips can be switched to a fast + unsafe mode, or to a slow + safe mode. And by default they are running in fast + unsafe mode.

    Important to notice that MacOS (and Windows, and single user Linux) are not affected because these attacks allow _attacking other users_ on the same machine if you have malware on your computer. For a single user computer, this doesn't add any new problems. Malware can attack the single user on a Mac anyway; being able to attack a second user is of very little importance.

    The only problem is browsers which try to run lots of untrusted code in a sandbox, and that's where Apple probably had to take some action that might have caused a performance decline. Since these attacks rely on highly accurate timers, I think Apple just makes its timers very inaccurate when it runs JavaScript code.
  5. DotCom2, Mar 15, 2018
    Last edited: Mar 15, 2018

    DotCom2 macrumors 68040

    Feb 22, 2009
    I did notice a bit of a slowdown on my iMac 27" 5K 2014 when it got patched for this. Just on the startup though .
    EDIT: Oh, and on the wake screen as well.
  6. AbSoluTc macrumors 601


    Sep 21, 2008
    Yes because you both have super secretive data that everyone wants! :rolleyes:

    It's a non issue for 99% of the world. Nobody is going to target the average person. There's nothing to gain. If I were going to exploit this flaw (which is pretty hard by the way), it would be on a Fortune 500 company, bank, intelligence agency or government agency that would net me something for my time and energy.

    Not to see your pr0n or access the $500 dollars you have in your bank account.
  7. Glmnet1 macrumors 6502a

    Oct 21, 2017
    Is this going to be applied to 8th gen CPUs already released? If so there would be 2 variants of those CPUs?

    It seems a bit rushed to reassure people. I'm afraid of the possible side effects such a quick fix could have.
  8. elvisimprsntr macrumors 6502

    Jul 17, 2013
    I expect the first round or two of CPU HW re-designs will have some technical problems/impacts.

    My mid '14 rMBP is humming along just fine. I think I can get at least another 3 years out of it. As for all my other Intel/ARM based devices (Apple, router/firewall, NAS, etc.), I am good for another 5 years.

    Thank you for reducing my home infrastructure CapX for the next 3-5 years. I might just take a vacation or buy a new car.
  9. Glmnet1 macrumors 6502a

    Oct 21, 2017
    So they just added the safety feature to calm people down but are not turning it on because it would affect performance too much?
  10. outskirtsofinfinity macrumors member


    Aug 2, 2017
    "Apple's software mitigations for the vulnerabilities have not resulted in any significant measurable decline in performance."

    Is there a citation for this?
  11. ljjycss macrumors member


    Apr 2, 2016
    8th-gen Core? Aren't kaby lake refresh, kaby lake G and coffee lake vulnerable to Meltdown and Spectre? Is Intel going to call Cannon lake 8th-gen Core? Intel really should clear their naming scheme.
  12. fairuz macrumors 68000


    Aug 27, 2017
    Silicon Valley
    These vulnerabilities were the best thing that ever happened to Intel. Now everyone is going to finally upgrade their CPUs. Sucks for anyone who bought an iMac Pro. Wish I had my brokerage account set up so I could have put in a fat buy on their down day when these were published.

    It's most likely not true for certain applications. Postgres has been shown to run much slower with the Linux patches, like 10-30%. I can't imagine Apple's done anything too different.
  13. Saipher macrumors demi-god


    Oct 25, 2014
    So I see you already have access to my data huh?... :)
  14. rtomyj macrumors 6502a


    Sep 3, 2012
    This is 100 percent correct. The likelihood someone can even get sensitive info from RAM from a consumer product is low. Imagine a server with gigs of password or user meta data. This exploit is wasted on consumers.

    Also, Apple patched it. You good.
  15. JPack macrumors 68040


    Mar 27, 2017
    The updated processors will have a new stepping.
  16. pentidoes macrumors 6502


    Jul 20, 2011
    Europe (what's left of it)
    Funny. A mere "obstacle" isn't what I was hoping for in a redesigned protection... (sigh)
  17. idunn macrumors 6502

    Jan 12, 2008

    Per my understanding the elephant in the room remains Intel ME (Management Engine). Only in public awareness a small unobtrusive mouse, quiet and unseen. But in reality a dragon.

    Intel says otherwise, that Intel ME is not a backdoor into one's computer, that it would never design or condone such a thing. Yet since 2008 this has been a fundamental feature incorporated into their chips, one that oversees all, is always on if any power present, cannot be seen or known by the computer owner, whose code remains secret. Thus one has only Intel's word that it has no nefarious purposes.

    So fine that they are addressing Spectre and Meltdown—after they became publicly known—but this is but part of the equation.

    Since Apple uses these chips it would be nice if they were more forthcoming than Intel has been. Mr. Cook assures us that our privacy is one of his key concerns, yet Apple seems silent on the news made public recently that another company with clients such as the NSA can hack into any iPhone. So, where exactly do we stand?
  18. BootsWalking macrumors 6502a

    Feb 1, 2014
    Linus has unreasonable opinions about how the user/kernel domains must be always separated, irrespective of the performance penalty. What he calls "unsafe" is only unsafe if someone finds an Meltdown-like exploit in the new design - and if they do Intel is providing a safety-valve to switch back to the hammer approach by turning off the "fast" mode.
  19. chabig macrumors 601

    Sep 6, 2002
    I don’t think that’s correct. macOS, Windows, and Linux are all multiuser systems with multiple levels of authenticated processes running concurrently. Whether you see it or not, you do have other “users” running on your system.
  20. iReality85, Mar 15, 2018
    Last edited: Mar 15, 2018

    iReality85 macrumors 6502a

    Apr 29, 2008
    Intel's 8th Generation is Coffee Lake, which is already released. So does this article mean 9th Generation?

    EDIT: This article is poorly worded and needs to be revised, as it is incredibly confusing and misleading.

    Brian Krzanich stated, "These changes will begin with our next-generation Intel® Xeon® Scalable processors (code-named Cascade Lake) as well as 8th Generation Intel® Core™ processors expected to ship in the second half of 2018." (emphasis mine)
  21. catportal macrumors regular


    Aug 11, 2016
    The crux of the problem is that speculative execution wasn't checking for memory protection bits. The only way to fix this is to check the memory protection bits, which introduces latency in that particular critical path. For most users this is completely unnecessary, which is why they have the unsafe mode.

    The software 'patch' for this is basically to use a separate stack for any system calls, which is slow because it requires flushing the tlb.
  22. coolfactor macrumors 68040

    Jul 29, 2002
    Vancouver, BC CANADA
    Do you restart your computer often? Macs have had industry-leading sleep mode for 20+ years. There's no need to shut down a Mac on a nightly basis.
  23. Lounge vibes 05 macrumors member

    May 30, 2016
    2 random questions:
    Will these be in the new Mac Pro?
    And whats with all the "Lake" names.
  24. The Cappy macrumors regular

    Nov 9, 2015
    Dunwich Fish Market
    How do you know? It might be a LOT of pr0n. ;)
  25. DotCom2 macrumors 68040

    Feb 22, 2009
    No, I don't. But when I have, I have noticed a bit of a slow down. More so, however, on the wake from sleep mode that I have noticed it takes longer to wake. At least on mine it does.

Share This Page