Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Intel & AMD cpu: add config (off by default) option that disables relevant security mitigations for huge (20-40%) performance uplift #1205

Open
ahydronous opened this issue Oct 24, 2024 · 0 comments

Comments

@ahydronous
Copy link

ahydronous commented Oct 24, 2024

I have a blurb in my own nixos config for certain CPUs to disable either retbleed and/or downfall mitigations.

Both of these are pretty much lab-only exploits that are virtually impossible to exploit without extreme setup and conditions. And at least for retbleed, the primary danger is to cloud providers, not personal computers. This is not worth paying a 20-40% (average 22.5%) performance cost for.

Nonetheless, I understand it would make people uncomfortable, so this "smart mitigations" option should be off by default.

retbleed affects Intel 6th-8th gen and AMD Zen1-Zen2+ afaik.
downfall affects Intel 6th-11th gen.

@ahydronous ahydronous changed the title Intel & AMD cpu: add config (off by default) option that disables relevant security mitigations for huge performance uplift Intel & AMD cpu: add config (off by default) option that disables relevant security mitigations for huge (20-40%) performance uplift Oct 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant