Panel: Meltdown, Spectre, and the free-software community Jonathan Corbet, Andrew ‘bunnie’ Huang, Benno Rice, Jess Frazelle, Katie McLaughlin, Kees Cook
- FreeBSD only heard 11 days beforehand. Would have liked more notice
- Got people involved from the Kernel Summit in Oct
- Hosting company only heard once it went official, been busy patching since
- Likely to be class-action lawsuit for $billions. That might make chip makers more paranoid about documentation and disclosure.
- Thoughts in embargo
- People noticed strange patches going in beforehand.
- Only broke 6 days early, had been going for 6 months
- “Linus is happy with this, something is terribly wrong”
- Sad that the 2nd-tier cloud providers didn’t know. Exclusive club and lines as to who got informed were not clear
- Projects that don’t have explicit relationship with Intel didn’t get informed
- Thoughts on other vendors
- This class of bugs could affect anybody, open hardware would probably not fix
- More open hardware could enable people to review the processors and find these from the design rather than poking around
- Hard to guarantee the shipped hardware matches the design
- Software people can build everything at home and check. FABs don’t work at home.
- Speculative execution warned about years ago. Danger ignored. How to make sure the next one isn’t ignored?
- We always have to do some risky stuff
- The research on this built up slowly over the years
- Even if you have only found impractical attacks against something doesn’t mean the practical one doesn’t exist.
- What criteria do we use to decide who is in?
- Mechanisms do exist, they were mainly not used. Perhaps because they were for software vulnerabilities
- Did people move providers?
- No but Containers made things easier to reboot stuff and shuffle
- Are there similar vulnerabilities ( similar or general hardware ) coming along?
- The Kernel page-table patches were fairly general, should cover many similar ones
- All these performance optimising bit of your CPU are now attack surfaces
- What are people going to do if this slows down hardware too much?
- How do we explain problems like these to politicians etc
- Legos
- We still have kernel devs getting their laptops
- Can be use CPUs that don’t have speculative execution?
- Not really. Back to 486s
- Who are we protesting against with the embargo?
- Everybody
- The longer period let better fixes get in
- The meltdown fix could be done in semi-public so had better quality
What is the most common street name in Australia? Rachel Bunder
- Why?
- Saw a map with most common name by US street
- Just looking at name, not end bit “park” , “road”
- Data
- PSMA Geocoded national address file – Great but came out after project
- Use Open Street Maps
- Started with Common Name in Sydney
- Used Metro Extracts – site closing down soon
- Format is geojson
- Road files separately provided
- Procedure
- Used python, R also has good features and libaraies
- geopandas
- Had some paths with no names
- What is a road? – “Something with a name I can drive a car on”
- Sydney
- Full street name
- Victoria Road
- Pacific Highway
- oops like like names are being counted twice
- Tried merging them together
- Roads don’t 100% match ends. Added function to fuzzy merge the roads that are 100m apart
- Still some weird ones but probably won’t affect top
- Second attempt
- Short st, George st, William st, John st, Church st
- Full street name
- Now with just the “name bit”
- Tried taking out just the last name. ended up with “the” as most common.
- Started with “The” = whole name
- Single word = whole name
- name – descriptor – suffex
- lots of weird names
- name list – Park, Victoria, Railway, William, Short
- Wouldn’t work in many other counties
- Now for all over Australia
- overpass data
- Downloaded in 50kmx50x squares
- Lessons
- Start small
- Choose something familiar
- Check you bias (different naming conventions)
- Constance vigerlence
- Know your problem
- Common plant names
- Wattle – 15th – 385
- Other name
- “The Esplanade” more common than “The Avenue”
- Top names
- 5th – Victoria
- 4th – Church – 497
- 3rd – George – 551
- 2nd – Railway
- 1st – Park – 693
- By State
- WA – Forest
- SA – Railway
- Vic – Park
- Tas – Esplanade
- NT – Smith/Stuart
- NSW – Park