Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-16 Thread Peder Rovelstad
Not that I've been able to find.  I think the next gen x64 did.  

-Original Message-
From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Kyle Marek
Sent: Tuesday, January 16, 2018 2:12 PM
To: list@lists.pfsense.org
Subject: Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw 
forces Linux, Windows redesign • The Register - patch to pfsense?

No speculative execution on your 32-bit machine?

On 01/16/2018 03:02 PM, Peder Rovelstad wrote:
> Back to my x86 Via box!  :/  Just when my Hyper-V x64 was really tuned...
>
> -Original Message-
> From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Rainer Duffner
> Sent: Tuesday, January 9, 2018 5:32 PM
> To: pfSense Support and Discussion Mailing List <list@lists.pfsense.org>
> Subject: Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw 
> forces Linux, Windows redesign • The Register - patch to pfsense?
>
>
>
>> Am 10.01.2018 um 00:14 schrieb Kyle Marek <pspps...@gmail.com>:
>>
>> This contradicts the majority of the purpose of virtualization.
>
> Interesting that you bring it up….
>
> I give you Theo de Raadt in late 2007:
>
>
> https://marc.info/?l=openbsd-misc=119318909016582 
> <https://marc.info/?l=openbsd-misc=119318909016582>
>
>
> ;-)
>
>
>
> Meanwhile, Netgate has published an updated statement:
>
> https://www.netgate.com/blog/an-update-on-meltdown-and-spectre.html 
> <https://www.netgate.com/blog/an-update-on-meltdown-and-spectre.html>
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-16 Thread Kyle Marek
No speculative execution on your 32-bit machine?

On 01/16/2018 03:02 PM, Peder Rovelstad wrote:
> Back to my x86 Via box!  :/  Just when my Hyper-V x64 was really tuned...
>
> -Original Message-
> From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Rainer Duffner
> Sent: Tuesday, January 9, 2018 5:32 PM
> To: pfSense Support and Discussion Mailing List <list@lists.pfsense.org>
> Subject: Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw 
> forces Linux, Windows redesign • The Register - patch to pfsense?
>
>
>
>> Am 10.01.2018 um 00:14 schrieb Kyle Marek <pspps...@gmail.com>:
>>
>> This contradicts the majority of the purpose of virtualization.
>
> Interesting that you bring it up….
>
> I give you Theo de Raadt in late 2007:
>
>
> https://marc.info/?l=openbsd-misc=119318909016582 
> <https://marc.info/?l=openbsd-misc=119318909016582>
>
>
> ;-)
>
>
>
> Meanwhile, Netgate has published an updated statement:
>
> https://www.netgate.com/blog/an-update-on-meltdown-and-spectre.html 
> <https://www.netgate.com/blog/an-update-on-meltdown-and-spectre.html>
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-16 Thread Peder Rovelstad
Back to my x86 Via box!  :/  Just when my Hyper-V x64 was really tuned...

-Original Message-
From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Rainer Duffner
Sent: Tuesday, January 9, 2018 5:32 PM
To: pfSense Support and Discussion Mailing List <list@lists.pfsense.org>
Subject: Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw 
forces Linux, Windows redesign • The Register - patch to pfsense?



> Am 10.01.2018 um 00:14 schrieb Kyle Marek <pspps...@gmail.com>:
> 
> This contradicts the majority of the purpose of virtualization.


Interesting that you bring it up….

I give you Theo de Raadt in late 2007:


https://marc.info/?l=openbsd-misc=119318909016582 
<https://marc.info/?l=openbsd-misc=119318909016582>


;-)



Meanwhile, Netgate has published an updated statement:

https://www.netgate.com/blog/an-update-on-meltdown-and-spectre.html 
<https://www.netgate.com/blog/an-update-on-meltdown-and-spectre.html>




___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-09 Thread Rainer Duffner


> Am 10.01.2018 um 00:14 schrieb Kyle Marek :
> 
> This contradicts the majority of the purpose of virtualization.


Interesting that you bring it up….

I give you Theo de Raadt in late 2007:


https://marc.info/?l=openbsd-misc=119318909016582 



;-)



Meanwhile, Netgate has published an updated statement:

https://www.netgate.com/blog/an-update-on-meltdown-and-spectre.html 





___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-09 Thread Kyle Marek
On 01/09/2018 05:58 PM, Gé Weijers wrote:
> On Wed, Jan 3, 2018 at 2:32 PM, Walter Parker  wrote:
>
>> On Wed, Jan 3, 2018 at 2:25 PM, Steve Yates  wrote:
>>
>>> I'm not a developer but I would think it's dependent on FreeBSD releasing
>>> the update, plus testing by pfSense/Netgate.  However, I would think
>>> there's not much concern with PCs running pfSense, since raw code would
>> not
>>> normally be running on the pfSense box...?
> Agreed, if someone manages to run malicious code on your pfSense box you
> have bigger problems.
I disagree. The fact that user processes can gain kernel-level access
*is* the bigger problem. A buffer overflow affecting a process running
as _dhcp would not otherwise result in such a severe issue.
> HOWEVER: running pfSense as a virtual machine may not be the best idea if
> you do not have full control over the other VMs running on the same
> hardware.

This contradicts the majority of the purpose of virtualization.

___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-09 Thread Gé Weijers
On Wed, Jan 3, 2018 at 2:32 PM, Walter Parker  wrote:

> On Wed, Jan 3, 2018 at 2:25 PM, Steve Yates  wrote:
>
> > I'm not a developer but I would think it's dependent on FreeBSD releasing
> > the update, plus testing by pfSense/Netgate.  However, I would think
> > there's not much concern with PCs running pfSense, since raw code would
> not
> > normally be running on the pfSense box...?
>

Agreed, if someone manages to run malicious code on your pfSense box you
have bigger problems.

HOWEVER: running pfSense as a virtual machine may not be the best idea if
you do not have full control over the other VMs running on the same
hardware.


-- 
--
Gé
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-03 Thread Walter Parker
On Wed, Jan 3, 2018 at 2:25 PM, Steve Yates <st...@teamits.com> wrote:

> I'm not a developer but I would think it's dependent on FreeBSD releasing
> the update, plus testing by pfSense/Netgate.  However, I would think
> there's not much concern with PCs running pfSense, since raw code would not
> normally be running on the pfSense box...?
>
> --
>
> Steve Yates
> ITS, Inc.
>
> -Original Message-
> From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Eero
> Volotinen
> Sent: Wednesday, January 3, 2018 10:47 AM
> To: pfSense Support and Discussion Mailing List <list@lists.pfsense.org>
> Subject: [pfSense] 'Kernel memory leaking' Intel processor design flaw
> forces Linux, Windows redesign • The Register - patch to pfsense?
>
> https://www.theregister.co.uk/2018/01/02/intel_cpu_design_flaw/
>
> is there patch soon available on pfsense kernel?
> ___
> pfSense mailing list
> https://lists.pfsense.org/mailman/listinfo/list
> Support the project with Gold! https://pfsense.org/gold
>

From the FreeBSD mailing list:

With respect to
https://newsroom.intel.com/news/intel-responds-to-
security-research-findings/

The FreeBSD Security Team recently learned of the details of these
issues that affect certain CPUs. Details could not be discussed
publicly, but mitigation work is in progress.

Work is ongoing to develop and commit these mitigations to the FreeBSD
repository as soon as possible, with updates for releases to follow.



Walter
-- 
The greatest dangers to liberty lurk in insidious encroachment by men of
zeal, well-meaning but without understanding.   -- Justice Louis D. Brandeis
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-03 Thread Steve Yates
I'm not a developer but I would think it's dependent on FreeBSD releasing the 
update, plus testing by pfSense/Netgate.  However, I would think there's not 
much concern with PCs running pfSense, since raw code would not normally be 
running on the pfSense box...?

--

Steve Yates
ITS, Inc.

-Original Message-
From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Eero Volotinen
Sent: Wednesday, January 3, 2018 10:47 AM
To: pfSense Support and Discussion Mailing List <list@lists.pfsense.org>
Subject: [pfSense] 'Kernel memory leaking' Intel processor design flaw forces 
Linux, Windows redesign • The Register - patch to pfsense?

https://www.theregister.co.uk/2018/01/02/intel_cpu_design_flaw/

is there patch soon available on pfsense kernel?
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


[pfSense] 'Kernel memory leaking' Intel processor design flaw forces Linux, Windows redesign • The Register - patch to pfsense?

2018-01-03 Thread Eero Volotinen
https://www.theregister.co.uk/2018/01/02/intel_cpu_design_flaw/

is there patch soon available on pfsense kernel?

Eero
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold