Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

31–40 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#33
How is it not illegal to do this without at least first ASKING the user for confirmation? I'd be annoyed but find it 'merely anti-consumer' rather than 'intentional destruction of property' if the BIOS refused to finish POST without the user confirming that yes, they want to sacrifice this CPU and make it (p)owned by $CORP.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#34
post #17

I'm not up on CPU terminology. I read the article and I don't know what this means. What is "locking" in this context? What is the "AMD PSB" ?

locking: At least some AMD CPUs (EPYC, TR PRO, Ryzen Pro) can have cryptographic keys burned into the silicon by the BIOS (Dell and Lenovo do that) Once a CPU has those keys burned into it, it is locked to motherboards of this specific vendor, because other motherboards don't have a BIOS that is signed with the cryptographic key that was burned in.

PSB: Platform Security Boot

PSP: Platform Security Processor (a CPU inside the CPU which handles e.g. the key burn in process)

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#35
post #27
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.

My first thought was, is it really a big deal to do that to your laptop's cpu? Then I saw that they're doing this to desktops. My next thought was, people buy pre-built desktops still?

Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#37
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#38
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

> OEM who trusts only their own cryptographically signed BIOS code to run on their platforms

It's not their platform after they sell it. We should resist this trend of referring to items as still belonging to their manufacturers, legitimizing their control over them, while we are reduced to mere users, paying for items but not owning them. Let's see how it sounds:

> An OEM who wants to restrict their customers from selling their CPU, or buying one second-hand, will use a PSB enabled..

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#39

Quoted post unavailable.

While avoiding Chinese-made computer components approaches impossibility the deeper you go, one vendor I'd trust not to fool around with AMD's PSB is System76. Not only are they non-shady, but they also try to open the firmware of the motherboards they use. While their AMD systems aren't quite there yet, the laptops they sell are.

https://github.com/system76/firmware-open

https://github.com/system76/ec

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#40
post #37
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.

See: The Sony PS3
Post reply on HN