Afaik, Project Zero only prove the exploit on Intel. AMD was warned, but they didn't seem to be able to actually check the exploit can work on AMD hardware until very recently.
Incorrect. They shown the exploit working on AMD A8 PRO. They even sent the code.
These materials are public. I've posted the link in reply to behrouz.
The setup for exploiting these vulnerabilities is very complex, so I'm not surprised this wasn't reproduced quicker.
All other companies succeeded.
As I said: Arm even managed to prove Meltdown vulnerability (PZ couldn't).
I expect more from a second largest CPU manufacturer. A lot more.
The report only said A8-9600 was vulnerable, but that's not Zen...
The role of security researchers like PZ is to find a vulnerability. It's manufacturers' role to further test them and check all CPU models they can find in storage.
In fact PZ worked with a fairly recent A8-9600 (it's already AM4). On the Intel side, it was a much older E5-1650 v3 from 2014 - possibly a hint on when they started working on this issue.
Either way, this is fixable, so it's all storm in a cup of water in the end.
No, it's not. The vulnerabilities will be patched (at least when we finally get patches that don't BSOD/brick computers), but we'll also learn a bit about the manufacturers.
Arm's reaction was perfect.
Intel's first reaction was... well... very typical for Intel. But they improved afterwards - also typical for them.
AMD's actions are not what we should expect. And AFAIK enterprise clients are far from amazed...
Once again: think about Meltdown.
The situation is as follows: researchers have suggested that the fundaments for a Variant 3 attack are also true for AMD CPUs. They didn't manage to make a successful attack, but they call it possible. The important part: they said exactly the same about ARM.
Arm admitted that their CPUs are vulnerable to all variants.
AMD said they
are not vulnerable to either Variant 2 and 3. Experts around the world reacted with "hey guys, but we've seen Variant 2 working!".
So a week later AMD said that "OK, you're right. Variant 2 is also an issue" and added "but we still
believe Variant 3 is not".
In the end a Variant 3 patch will also be applied to AMD systems anyway, so I don't know why they're fighting so much. It's like they didn't care about EPYC sales at all (in fact something I
believe to be true
).