<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[HyperForum — Spectre mitigations]]></title>
	<link rel="self" href="https://forums.hyperbola.info/extern.php?action=feed&amp;tid=717&amp;type=atom" />
	<updated>2022-08-27T19:16:48Z</updated>
	<generator>PunBB</generator>
	<id>https://forums.hyperbola.info/viewtopic.php?id=717</id>
		<entry>
			<title type="html"><![CDATA[Re: Spectre mitigations]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=4931#p4931" />
			<content type="html"><![CDATA[<p>dikasp2 you made me laugh out loud! But yes - OpenBSD mitigations sound fabulous! </p><p>throgh - Looking forward to this exciting new evolution!</p><p>Didn&#039;t know OpenBSD - or any BSD - was my kind of thing, even, but I do now <img src="https://forums.hyperbola.info/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></content>
			<author>
				<name><![CDATA[auanta]]></name>
			</author>
			<updated>2022-08-27T19:16:48Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=4931#p4931</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Spectre mitigations]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=4929#p4929" />
			<content type="html"><![CDATA[<p>GNU/Linux-libre is for us surely a point to stay for the moment: Nevertheless we are working onto HyperBK and therefore porting the kernel building with a free and libre toolchain also. HyperbolaBSD itself is therefore the major goal and our GNU/Linux-libre is more the point of transitiion. When we can include more mitigations, we will do that also for GNU/Linux-libre. <img src="https://forums.hyperbola.info/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></content>
			<author>
				<name><![CDATA[throgh]]></name>
				<uri>https://forums.hyperbola.info/profile.php?id=347</uri>
			</author>
			<updated>2022-08-27T18:44:32Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=4929#p4929</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Spectre mitigations]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=4922#p4922" />
			<content type="html"><![CDATA[<p>i see @aunta now you are paranoid type <img src="https://forums.hyperbola.info/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /> .</p><p>first just make some tea and relax, the nations are in needs for hard workers like you <img src="https://forums.hyperbola.info/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />i will describe the things as i can below.</p><p>first in hyperbola gnu linux stage: unless you are a big boss who holds a lot of money or power or engaged with mafia, yakuza, or deepweb activities you may rest assured that malicious hacker probably has no interest to exploit your computer. your chances on accidentaly meet malicious code and robots are pretty slim as well and those malicious code first must breach into your system too.</p><p>second stage when hyperbsd is finished: if you still paranoid with first stage, you dont have to worry anymore as hyperbsd based on a super secure openbsd, no advanced tweaks needed as these distribution are secure from the ground up.</p><p>you might find many articles on the net this is the example one:<br /><a href="https://why-openbsd.rocks/fact/meltdown-spectre/">https://why-openbsd.rocks/fact/meltdown-spectre/</a></p>]]></content>
			<author>
				<name><![CDATA[dikasp2]]></name>
				<uri>https://forums.hyperbola.info/profile.php?id=482</uri>
			</author>
			<updated>2022-08-27T16:05:10Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=4922#p4922</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Spectre mitigations]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=4918#p4918" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>throgh wrote:</cite><blockquote><p>Well, Hyperbola won&#039;t install any kind of mirocode. That is especially the point about rejecting firmware-blobs. To make that part clear: <strong>We will never include binary blobs into the Hyperbola-system being not open before compilation.</strong></p><p>For GNU/Linux-libre there are therefore only that mitigations available we have done. HyperbolaBSD will get even more attention possible!</p></blockquote></div><br /><p>I&#039;m not asking for binary blobs to be included in the kernel, not at all. I don&#039;t have the knowledge about what intel microcode even is. Are we sure that those are blobs? Or are they just patches?</p><p>Forgive me,, for I have been working a lot and am tired but I wanted to get this out</p><p>From the responses so far I think we need to re-look at what mitigations are available. The mainline Linux kernel has made mitigations but some options apparently have to be turned on in the compile process. So, it would just be a matter setting the defaults for the Linux-libre kernel at compile time to cover these vulnerabilities. The issue I see on my computer is that some but not all have been &#039;patched&#039; or configured with the safe defaults.</p><p>With that being the case, the safe defaults are in line with Hyperbola policy</p><p>Unless I totally misunderstood, tho. But I do gather that microcode is but only one of the mitigations, the other is changes to the kernel itself. It must be stressed that Spectre affects even ARM and MIPS cpus, and I am left with the impression that this affects all kernels</p><p>Information can be found here and some astute kernel person can make the appropriate decisions: </p><p><a href="https://docs.kernel.org/admin-guide/hw-vuln/">https://docs.kernel.org/admin-guide/hw-vuln/</a><br /><a href="https://docs.kernel.org/admin-guide/hw-vuln/spectre.html">https://docs.kernel.org/admin-guide/hw- … ectre.html</a><br /><a href="https://wiki.archlinux.org/title/Microcode">https://wiki.archlinux.org/title/Microcode</a><br /><a href="https://wiki.archlinux.org/title/Security#CPU">https://wiki.archlinux.org/title/Security#CPU</a></p><p>Excited for HyperbolaBSD-libre btw</p>]]></content>
			<author>
				<name><![CDATA[auanta]]></name>
			</author>
			<updated>2022-08-27T15:41:23Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=4918#p4918</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Spectre mitigations]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=4909#p4909" />
			<content type="html"><![CDATA[<p>@auanta besides, many of those blobs could have unknown risks..</p>]]></content>
			<author>
				<name><![CDATA[zapper]]></name>
				<uri>https://forums.hyperbola.info/profile.php?id=117</uri>
			</author>
			<updated>2022-08-27T13:42:35Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=4909#p4909</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Spectre mitigations]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=4901#p4901" />
			<content type="html"><![CDATA[<p>Well, Hyperbola won&#039;t install any kind of mirocode. That is especially the point about rejecting firmware-blobs. To make that part clear: <strong>We will never include binary blobs into the Hyperbola-system being not open before compilation.</strong></p><p>For GNU/Linux-libre there are therefore only that mitigations available we have done. HyperbolaBSD will get even more attention possible!</p>]]></content>
			<author>
				<name><![CDATA[throgh]]></name>
				<uri>https://forums.hyperbola.info/profile.php?id=347</uri>
			</author>
			<updated>2022-08-27T09:40:22Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=4901#p4901</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Spectre mitigations]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=4894#p4894" />
			<content type="html"><![CDATA[<p>I was wndering if Hyperbola would be seeking to have mitigations for the vulnerabilities listed here:</p><p>spec_store_bypass:Vulnerable</p><p>spectre_v2:Vulnerable: eIBRS with unprivileged eBPF<br />grep $ /sys/devices/system/cpu/vulnerabilities/*</p><p>Currently there remain a few open vulnerabilities as far as my kernel tells me.</p><p>Also I think we require packages to install &quot;microcode&quot;, I am not sure of their licenses but they aren&#039;t in our </p><p>Mitigations should be loaded early in boot process per Arch wiki, before the initramfs</p>]]></content>
			<author>
				<name><![CDATA[auanta]]></name>
			</author>
			<updated>2022-08-27T06:43:27Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=4894#p4894</id>
		</entry>
</feed>
