Hi all,
The following is a mixture of facts and speculations but never the less in my opinion means a paradigm shift for the virtualization industry!
First the facts:
1) Virtualization as a driving factor first began in this decade
2) According to Intel any CPU before 2011 (Westmere) is not affected by Meltdown and Spectre
3) The virtualization industry almost exclusively uses the Intel platform
4) The fix for Meltdown hurts performance of Intel CPU's by an order of magnitude more than other platforms - AMD, ARM, Sparc
5) The fix for a large part of this performance hit is to activate a new CPU feature only implemented in Intel CPU's - who dares activate this since it is some other "clever" manipulation of host memory?
6) Meltdown is particularly a problem for the virtualization industry since Meltdown completely destroys the perceived security gained by isolation of virtual guest on a host - remember you can gain access to any other virtual guest's memory running on the same host.
My own findings on my Opteron based servers:
1) Whether the fix for Meltdown is activated or not (pki on or off) have no, or only marginally performance implications
2) The new CPU feature to activate to circumvent performance degration is not available on Opteron CPU's
3) It seems to be the same picture for Ryzen
To sum it all up: In my opinion any professionel and security concerned virtualization business which have their customers need in mind should start there move away from Intel to Ryzen better today than tomorrow.
What is your opinion?
The following is a mixture of facts and speculations but never the less in my opinion means a paradigm shift for the virtualization industry!
First the facts:
1) Virtualization as a driving factor first began in this decade
2) According to Intel any CPU before 2011 (Westmere) is not affected by Meltdown and Spectre
3) The virtualization industry almost exclusively uses the Intel platform
4) The fix for Meltdown hurts performance of Intel CPU's by an order of magnitude more than other platforms - AMD, ARM, Sparc
5) The fix for a large part of this performance hit is to activate a new CPU feature only implemented in Intel CPU's - who dares activate this since it is some other "clever" manipulation of host memory?
6) Meltdown is particularly a problem for the virtualization industry since Meltdown completely destroys the perceived security gained by isolation of virtual guest on a host - remember you can gain access to any other virtual guest's memory running on the same host.
My own findings on my Opteron based servers:
1) Whether the fix for Meltdown is activated or not (pki on or off) have no, or only marginally performance implications
2) The new CPU feature to activate to circumvent performance degration is not available on Opteron CPU's
3) It seems to be the same picture for Ryzen
To sum it all up: In my opinion any professionel and security concerned virtualization business which have their customers need in mind should start there move away from Intel to Ryzen better today than tomorrow.
What is your opinion?