¿Seguridad o prestaciones? Compromisos
No estoy muy seguro sobre en qué habrá terminado esto pero me parece interesante por varios motivos: Ubuntu disables Intel GPU security mitigations, promises 20% performance boost.
Por un lado, está claro que añadir controles de seguridad hace que el código sea más lento (en este caso parece que mucho), y más complejo (se añaden instrucciones para vigilar que no pasen cosas y estar seguros de que sucden las adecuadas).
En este caso, además, los controles de seguridad vienen de un fallo de diseño por la ejecución predictiva (Recordar “Meltdown” and “Spectre:” Every modern processor has unfixable security flaws).
Según Ubuntu, este sería un problema suficientemente bien manejado en el kernel y, por lo tanto, los controles que añadían serían innecesarios.
At this point, Spectre has been mitigated in the kernel, and a clear warning from the Compute Runtime build serves as a notification for those running modified kernels without those patches. For these reasons, we feel that Spectre mitigations in Compute Runtime no longer offer enough security impact to justify the current performance tradeoff.
La ganancia no es pequeña, como dice el titular: un 20% de mejora.
Más aún, parece que estos fallos no están siendo atacados porque el esfuerzo no compensa (aunque ya sabemos que todo depende del sistema y el nivel de la información que protege).
“Nobody bothers attacking these vulns because it takes a lot of engineering time to implement attacks against them to any useful level of rigor, and getting any interesting data back outside very targeted scenarios is very unlikely (plus it’s noisy due to the number of iterations you need to do on these types of side-channels),” independent researcher Graham Sutherland wrote on Mastodon. “The economics just don’t stack up for attackers, especially when there are so many lower-effort higher-reward attack approaches they can throw at stuff.”
Interesante.




