These old bricks don’t get microcode updates for the CPU which means you will be vulnerable to many Spectre and Meltdown attacks. QubesOS can mitigate it to some degree such as by disabling hyperthreading, but QubesOS can’t mitigate it completely, only microcode updates can and these old bricks don’t receive them.

as I know linux is capable of loading its own, updated cpu microcode at boot time. I’m not sure if it’s being done by default, but this article probably means that it isn’t

but the main thing is that built-in microcode version is probably not that bad of a problem if you take care of it

@chappedafloat@lemmy.wtf
creator
link
fedilink
0
edit-2
8d

deleted by creator

do you mean this part?

However, some of the vulnerabilities of this class cannot be effectively mitigated without updated CPU microcode.

(https://osresearch.net/Heads-threat-model/)

linux can do microcode updates. I think what they wanted to mean is that the general mitigations (the retpolines and the page table isolation they mention near it) are what is not enough

@chappedafloat@lemmy.wtf
creator
link
fedilink
2
edit-2
8d

deleted by creator

I guess you can do that on Linux as well by disabling kvm passthrough of the GPU to the VMs.

I think it is disabled by default, and you would need to enable it for a specific VM. as I know, the GPU can rarely be shared to multiple VMs

I think QubesOS only does mitigations, not microupdates.

it may be possible to do it on Qubes too. I think the microcode updates are not OS-specific, but I’m not certain about this

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 3.13K Posts
  • 78.3K Comments
  • Modlog