Slashdot Mirror


AMD/ATI Video Drivers: Unsafe At Any Speed

An anonymous reader writes "CERT/CC has called out AMD for having insecure video drivers. AMD/ATI video drivers are incompatible with system-wide ASLR. 'Always On' DEP combined with 'Always On' ASLR are effective exploit mitigations. However, most people don't know about 'Always On' ASLR since Microsoft had to hide it from EMET with an 'EnableUnsafeSettings' registry key — because AMD/ATI video drivers will cause a BSOD on boot if 'Always On' ASLR is enabled."

19 of 261 comments (clear)

  1. Crappy AMD drivers?! by LingNoi · · Score: 4, Insightful

    This isn't very surprising AMD/ATI have always had crappy drivers. I wish their fan base would stop apologising for them and demand AMD put more effort into their products.

    1. Re:Crappy AMD drivers?! by Anonymous Coward · · Score: 5, Funny

      You're absolutely right; AMD's drivers rarely allow you to play games.

    2. Re:Crappy AMD drivers?! by LingNoi · · Score: 5, Insightful

      I never mentioned Nvidia, it's also completely irrelevant as AMD drivers will suck regardless of what Nvidia does.

    3. Re:Crappy AMD drivers?! by Mitchell314 · · Score: 4, Insightful

      Linux sucks, it just happens that everything else is even worse. :D

      --
      I read TFA and all I got was this lousy cookie
    4. Re:Crappy AMD drivers?! by Bengie · · Score: 4, Funny

      More stable than water anyway.

    5. Re:Crappy AMD drivers?! by Skarecrow77 · · Score: 4, Insightful

      crying about fanboys while running around fanboying. typical.

      all fanboys suck. end of story. mint vs ubuntu, google vs apple, nintendo vs sega, fuckin coke vs pepsi... if you're on one side of an arguement, and you can't see the cons of your own side as well as the pros of the other side, you don't really understand the arguement and you shouldn't be speaking.

    6. Re:Crappy AMD drivers?! by Skarecrow77 · · Score: 4, Funny

      wow. somehow click on the wrong reply button and reply to myself. so i look like an idiot. bah, i'm going to lunch.

    7. Re:Crappy AMD drivers?! by Skarecrow77 · · Score: 4, Insightful

      depends on your definition of failure.

      if gnu/linux was aiming to become the predominant desktop OS, displacing microsoft, then it certainly has failed

      if gnu/linux was aiming to beocme a major player in the arena, maybe not the overall leader but boasting enough of a market percentage that it couldn't be successfully ignored or neglected by software devlopers and hardware OEMs, then yeah... it's probably failing at that too.

      if gnu/linux was aiming to become a viable alternative to the market leaders for people who care about free software and people who care about being in full control of their own OS, well it has become a rousing success at that.

  2. AOD by Kjella · · Score: 5, Insightful

    Acronym Overload Detected. A summary is supposed to summarize but I couldn't tell what this story is about unless I already know.

    --
    Live today, because you never know what tomorrow brings
    1. Re:AOD by Obfuscant · · Score: 5, Insightful

      Notice that the first reference to ASLR in the summary is actually a link to Wikipedia.

      And the reference to EMET is a link to a microsoft page that has at the top this warning:

      This article applies to a different operating system than the one you are using. Article content that may not be relevant to you is disabled.

      I'm reading this on a linux system, but I manage several windows boxes. It's very useful for microsoft to refuse to diplay content it decides I don't need to see. Thank you.

    2. Re:AOD by noh8rz3 · · Score: 5, Informative

      aslr = a way to secure your memory so it's harder for malware to run attacks.
      EMET = a bunch of tools that windows uses to secure the machine. aslr is one of these tools
      bsod = blue screen of death. your computer is frozen
      AMD = a company that was formerly known for making computer chips, but is now in the graphics card business
      ATI = a graphics card manufacturer that AMD bought.
      DEP = another tool in the EMET toolkit.
      cert/cc = an organization that is viewed as an authority on computer stuff.

      in short, AMD drivers suck so much that microsoft has to override its own computer protections to keep AMD from crashing your machine. so the drivers are not just unstable, they make your machine more vulnerable to malware. cert says, "epic fail".

  3. Re:There is nothing in this story connecting ATI/A by tlhIngan · · Score: 4, Informative

    The story is about DEP and ASLR effectiveness at blocking exploits. IT has nothing to do with the title or the ATI/AMD aspect.

    The CERT article mentions it, and it mentions it in that you cannot use the DEP/ASLR protections (in the kernel) because ATI/AMD make an incompatible driver. And since graphics drivers are kernel things, loading them means the kernel must disable DEP/ASLR, making your machine just that much less secure because of it.

  4. ASLR by Jeremiah+Cornelius · · Score: 5, Insightful

    Preventing yesterday's attacks, tomorrow.

    --
    "Flyin' in just a sweet place,
    Never been known to fail..."
    1. Re:ASLR by blackraven14250 · · Score: 5, Informative

      Better to prevent yesterday's attacks at all than to leave the hole open for all time...

    2. Re:ASLR by osu-neko · · Score: 5, Insightful

      Given that "yesterday's attacks" compromise 99% of the attacks that occur every day, that seems wise.

      --
      "Convictions are more dangerous enemies of truth than lies."
  5. MS should just deny them WHQL certification by PingXao · · Score: 4, Insightful

    Microsoft is constantly telling people that they won't sign their drivers unless they pass strict quality and certification standards. MS should just deny that to drivers as buggy as these are reported to be.

    Oh wait... that would mean MS Is actually committed to quality as opposed to just needing an excuse to deny the little guy who wants to write some driver-level code.

  6. Re:AMD's proprietary Linux driver is secure... by TeknoHog · · Score: 4, Informative

    $ lsmod | grep fglrx; uptime
    fglrx 3029147 144
    agpgart 26120 3 intel_gtt,intel_agp,fglrx
    22:41:37 up 76 days, 4:30, 8 users, load average: 0.00, 0.01, 0.05

    --
    Escher was the first MC and Giger invented the HR department.
  7. But it still showed you the article content! by Anonymous Coward · · Score: 4, Informative

    ... you failed to mention that. Oh, right. Your goal was to be sensational. Carry on.

    1. Re:But it still showed you the article content! by drinkypoo · · Score: 4, Insightful

      1) Don't start your post in the subject line, that is fucking annoying. Are you new?
      2) What do you mean "the" article content? He doesn't know which content it showed him, and neither do you. But I notice you're anonymous and cowardly, so you're probably a shill as well.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"