
With more Spectre attacks being discovered and disclosed each month, the pressure on Intel to fix these issues in their future products is enormous. Not only was it disclosed in January 2018 that all Intel processors dating back to 1995 were prone to leaking sensitive information, the range of Spectre vulnerabilities was expected to increase as new ways of breaking Intel’s security were uncovered. The vulnerabilities relate to how modern processors will speculate on what code needs to be run or executed in the future, and will run that code ahead of time if it is not dependent on any existing process. To mitigate these and other attacks in the future, the developers of the OpenBSD Unix project have stated their plans to disable hyperthreading support in all future Intel processors.
According to OpenBSD maintainer Mark Kettenis, the group was moving to disable hyperthreading because it allowed for future attacks like Spectre to be run on Intel processors, regardless of how secure Intel might make them in the future. The use of the feature, says Kettenis, “can make cache timing attacks a lot easier and we strongly suspect that this will make several spectre-class(sic) bugs exploitable.”
Disabling hyperthreading is easier than the alternative, which is to change the way the scheduler works in OpenBSD to better secure the operating system. If an attacker knows enough about what they’re looking for, it could be possible to examine how a process runs on a virtual thread to determine its contents. Virtual threads or cores are able to share a physical core to allow for code to be executed in parallel, but virtual threads can be monitored to determine the contents of their workload.
As an example, Usain Bolt’s average speed is 37.58 km/h, and you can time when he leaves the room, runs around the block at his average speed, and comes back again. By knowing the duration of his run and his average speed, it is possible to estimate the distance he would have ran to a certain degree of accuracy. In the same way, you can estimate the workload of a core or thread, and try figure out its contents by either measuring the thread’s performance, or getting it to leak data into the chip’s cache to allow it to be read directly.
The OpenBSD group will be disabling hyperthreading by default for all Intel processors in the future, and will eventually allow for the same change to be made for processors from other processors like AMD Zen, IBM Power, and Sparc. Re-enabling the feature will be possible by modifying a parameter in the boot files, which means that users can decide for themselves whether security is more important than the possible speed-up their workload might gain from enabling the feature.
Although the OpenBSD group’s decisions typically don’t affect other opensource projects, we might see Linux distributions such as Ubuntu and Fedora Project adopt the same idea in future versions of their operating systems, and if this proves viable we might see the same thing being done by Apple and Microsoft in the future.
