A <\/span>new research paper<\/span><\/a> (PDF warning) details a new speculative execution, side-channel CPU exploit that can dramatically speed up some previously known attack types. All modern Intel processors, going back to the original <\/span>Intel Core architecture<\/span><\/a> from 2006 are vulnerable to this exploit.<\/span><\/p>\n As the paper states:<\/span><\/p>\n \u201cThe root cause for SPOILER is a weakness in the address speculation of Intel\u2019s proprietary implementation of the memory subsystem, which directly leaks timing behavior due to physical address conflicts. Existing spectre mitigations would therefore not interfere with SPOILER\u201d<\/span><\/p><\/blockquote>\n Intel was informed of these findings on December 1, 2018. AMD has <\/span>released a short statement<\/span>, where <\/span>they confirm<\/span><\/a> that their products are not vulnerable to SPOILER.<\/span><\/p>\n This is another piece of bad news for Intel. <\/span>Initial analysis indicates<\/span><\/a> that this exploit may be extremely difficult to patch at the software level. Patching at the microcode level could have a serious impact on performance.<\/span><\/p>\n That is a good question. Personally, I am more worried about more primitive, well-known attack methods, especially when it comes to SQL Server. Things like <\/span>SQL injection attacks<\/span><\/a>, applications using sys admin rights, and people running seriously unpatched systems. Getting those barn doors closed should be a much higher priority for most organizations.<\/span><\/p>\n What do you think? Were you concerned about the Spectre\/Meltdown exploits in early 2018<\/a>? Did you do any specific patching for that? I believe in digital \u201c<\/span>herd immunity<\/span><\/a>\u201d meaning that if a large percentage of the population does a good job of securing and patching their systems, it will help protect everyone. Plus, if you do a <\/span>good job protecting your system<\/span><\/a>, a higher percentage of lower skill attackers will look for an easier target.<\/span><\/p>\n \u00a0<\/span><\/p>\n At the Open Compute Project (OCP) Global Summit 2019, Intel <\/span>showed and demonstrated<\/span><\/a> several new 100GbE adapters that use the OCP NIC 3.0 form factor. These are relatively small daughter cards that easily fit horizontally in 1U servers. Intel is a little late to the 100GbE market, behind vendors like Mellanox. Despite this, having more vendors to choose from is a good thing. Intel did a short presentation about the OCP NIC 3.0 specification at the OCP Global Summit that <\/span>you can watch here<\/span><\/a>.<\/span><\/p>\n \u00a0<\/span><\/p>\n With AMD\u2019s 7nm Ryzen 3000 mainstream desktop processors getting closer to release (probably announced at the <\/span>Computex 2019<\/span><\/a> show), Intel needs a competitive response for 2019. This <\/span>appears to be<\/span><\/a> a new 14nm <\/span>Comet Lake<\/span><\/a> family that may also be released in mid-2019. <\/span>These are rumored<\/span><\/a> to have up to 10 physical cores for desktop chips and up to eight physical cores for mobile chips.<\/span><\/p>\n It is unclear at this point whether these Comet Lake processors will work in existing Intel Z390 motherboards. Intel has a pretty mixed track record when it comes to backwards compatibility for motherboards, but perhaps they are changing their ways.<\/span><\/p>\n These processors should perform quite well on heavily multi-threaded workloads, and they will give you another alternative to jumping up to a more expensive HEDT system. This line of processors will have to compete with the AMD Ryzen 3000 processors.<\/span><\/p>\n Current speculation<\/span><\/a> is that the 7nm AMD Ryzen 3000 series may have up to 16 physical cores in a mainstream desktop processor. The Ryzen 3000 series may also have better single-threaded performance than Comet Lake. If both of these rumors are true, it will be a huge achievement for AMD that will put a lot of pressure on Intel.<\/span><\/p>\n Figure 1: AMD Ryzen 3000 Desktop Processor<\/strong><\/span><\/b><\/p>\n Healthy competition between Intel and AMD is good for consumers, and I hope it continues. Like many people, I was very tired of Intel rolling out annual product updates of four-core processors with very marginal performance increases. They had been doing this for the past 4-5 years, and they could get away with it because AMD just wasn\u2019t competitive. That is no longer the case.<\/span><\/p>\n \u00a0<\/span><\/p>\n Speaking of Intel changing their ways, <\/span>they have hired Kyle Bennett<\/span><\/a> (the founder of the HardOCP web site<\/a>), starting April 1, 2019. He will be the Director of Enthusiast Engagement for their Technology Leadership Marketing group.<\/span><\/p>\n As a result, the HardOCP website will be \u201cmothballed\u201d with no new content. The HardForum will be demonetized and sold but will stay in operation. I have been a long-time reader of HardOCP, so I am sorry to see it essentially going away. This is a great opportunity for Kyle, and it is one piece of evidence that Intel is <\/span>trying to change their image<\/span><\/a>. This is <\/span>similar to Ryan Shrout<\/span><\/a> of PC Perspective <\/span>going to Intel last October<\/span><\/a> as their Chief Performance Strategist.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":" (Glenn\u2019s Technical Insights\u2026 used to be part of our bi-weekly newsletter but we decided to make it a regular blog post instead so it can get more visibility. It covers interesting new hardware and software developments that are generally relevant for SQL Server). \u00a0 AMD Processors Not Vulnerable to SPOILER CPU Exploit A new research […]<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[432,17],"tags":[433],"class_list":["post-1546","post","type-post","status-publish","format-standard","hentry","category-glenns-technical-insights","category-sql-server-hardware","tag-glenns-tech-insights"],"yoast_head":"\nShould You Be Worried?<\/span><\/span><\/h3>\n
Intel Demonstrates 100GbE OCP NIC 3.0 Adapters<\/span><\/span><\/h2>\n
Intel Comet Lake Processors Coming Soon<\/span><\/span><\/h2>\n
AMD Ryzen 3000<\/span><\/span><\/h3>\n
<\/a><\/span><\/p>\nIntel Hires Kyle Bennet of HardOCP<\/span><\/span><\/h2>\n