/srv/irclogs.ubuntu.com/2019/12/02/#ubuntu-kernel.txt

kantlivelongis there list of kernel command line options to disable security mitigation for recent cpu exploits?16:21
gpiccolikantlivelong, I think "mitigations=off" will do the job, by disabling all of them16:27
kantlivelongthats 5.2+ kernel though right?16:28
kantlivelongsuppose i could update16:28
gpiccoliIt's backported to older kernels in our releases, let me check for you kantlivelong 16:29
kantlivelongah16:29
gpiccolikantlivelong, for Bionic (4.15): https://kernel.ubuntu.com/git/ubuntu/ubuntu-bionic.git/tree/Documentation/admin-guide/kernel-parameters.txt#n245216:30
kantlivelongah cool16:30
kantlivelongthats what i was lookin for16:30
gpiccoliThis file explain the fine tunnings to the mitigations, like to disable a mitigation for a single issue (Spectre only for example)16:30
gpiccoliGreat =)16:31
gpiccoliThis is on Disco (5.0): https://kernel.ubuntu.com/git/ubuntu/ubuntu-disco.git/tree/Documentation/admin-guide/kernel-parameters.txt#n256716:31
gpiccoliSAme thing basically heheh16:31
gpiccoliYou may be using 5.0 as Bionic HWE for example16:31
kantlivelonggonna give this a shot16:32
gpiccolicool, hope it helps you16:32
kantlivelongonly real concern is js but think firefox mitigated that 16:32
gpiccoliHmm..not sure about that. The advise is usually to keep mitigations enabled, although I can see how it may affect some workloads' performance heheh16:33
kantlivelongotherwise its all trusted code running16:33
gpiccoliIt's a per-case decision I guess16:33
kantlivelongdesktop gaming/dev pc16:33
kantlivelongolder16:33
kantlivelongtyty16:34
gpiccoliyw =)16:35
JanCmaybe don't do banking on it16:42
JanCor similar16:42
kantlivelongor just close ff and open w/ bank alone16:43
JanCand development might depend on what sort; if it's all open source there are probably easier ways to "steal" your code, like using git...  ;)16:43
kantlivelongno real concern other than ff16:43
tyhickskantlivelong: firefox reduced their timer precision which makes it more difficult to carry out speculative attacks using JS16:46
JanCwhich means an attack would probably take a lot longer16:46
tyhickshttps://www.mozilla.org/en-US/security/advisories/mfsa2018-01/16:48
tyhicksthey call it a partial, short-term mitigation (which is a fair description)16:48
tyhicksI don't know if they've done anything in addition to that initial change16:48
JanCprobably not much else they can do without removing functionality16:49
=== mamarley_ is now known as mamarley
=== joedborg_ is now known as joedborg
=== vaishali_ is now known as vaishali
=== kantlive- is now known as kantlivelong
=== kloeri_ is now known as kloeri
shibbolethfor some reason the verbose boot text, desktop, picture on the screen is "more grey" (dunno how to put it) wheen booting kernel 5.3 vs 4.1522:16
shibbolethno such issue in 5.022:16
shibbolethin short, my displays look at lot cheaper when booting 5.3 :)22:16
shibbolethdisplays connected by displayport, intel skylake graphics22:17
shibbolethimagine looking at a cheap-ass LCD vs a decent one at best buy. one has excellent black, the other will be tainted by a grey hue22:17
shibbolethbooting debian testing kernel 5.3=no issue22:21
shibbolethubuntu 18.04-hwe-edge was affected both before and after todys update22:22

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!