Quoted post unavailable.
Lenovo vendor locking Ryzen CPUs with AMD PSB
31–40 of 234 posts
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#32I'm not up on CPU terminology. I read the article and I don't know what this means. What is "locking" in this context? What is the "AMD PSB" ?
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#33Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#34I'm not up on CPU terminology. I read the article and I don't know what this means. What is "locking" in this context? What is the "AMD PSB" ?
PSB: Platform Security Boot
PSP: Platform Security Processor (a CPU inside the CPU which handles e.g. the key burn in process)
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#35This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…
Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.
Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#36Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#37This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#38This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…
It's not their platform after they sell it. We should resist this trend of referring to items as still belonging to their manufacturers, legitimizing their control over them, while we are reduced to mere users, paying for items but not owning them. Let's see how it sounds:
> An OEM who wants to restrict their customers from selling their CPU, or buying one second-hand, will use a PSB enabled..
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#39Quoted post unavailable.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#40This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…
A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.