Earlier quoted context omitted.
Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.
My first thought was, is it really a big deal to do that to your laptop's cpu? Then I saw that they're doing this to desktops. My next thought was, people buy pre-built desktops still? Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.
Lenovo vendor locking Ryzen CPUs with AMD PSB
41–50 of 234 posts
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#42Quoted post unavailable.
Are there any that are not manufactured in China?
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#43First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server.
But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually have a remote KVM feature, so you could e.g. boot the OS into recovery mode)
It does not prevent any other attacks, because you could still swap out the CPU. The servers usually just quietly burn the CPUs, so you wouldn't notice if the CPUs were replaced by an attacker.
Second, this produces a lot of unnecessary e-waste. About 99% of all hardware (except HDDS) from datacenters is sold on the second hand market. Locked CPUs are essentially worthlese, especially if buyers or sellers don't know and throw the CPU away because they think it's defective.
Third, this opens up a MASSIVE attack surface. Imagine if somebody finds a bug im the PSP (Platform Security Processor, a CPU inside the CPU that handles the locking thing amon g other things) and is able to burn arbitrary keys into the CPU. The attacker would randomly generate a key and burn them into the CPU. You could permanently kill an entire datacenter with that within seconds.
Or if somebody manages to write a malicious BIOS version and flash it to servers which usually don't have a locked BIOS. This BIOS version would also burn a random key into the CPU with the same result: You can easily permanently destroy an entire datacenter.
I think this is just AMD's greediness again in the cloak of "improving security"
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#44Quoted post unavailable.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#45Quoted post unavailable.
Are there any that are not manufactured in China?
https://indianexpress.com/article/technology/tech-news-techn...
Of course, I assume lots of components for those are made in China.
Samsung might make in South Korea? Asus in Taiwan?
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#46Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#47Earlier quoted context omitted.
Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.
My first thought was, is it really a big deal to do that to your laptop's cpu? Then I saw that they're doing this to desktops. My next thought was, people buy pre-built desktops still? Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.
If you are enthusiast and need a one or two desktops, then probably not. If you need to procure several hundred of them every few months, then probably yes.
What this definitely will do is to affect the market price of these desktops once the lease (or depreciation time) runs out and owner will try to unload them on second hand market.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#48The AMD PSB can also be used to lock down a processor to enforce secure boot and thus don't let you run an unsigned operating system, i.e. no longer allowing you to run Linux on your machine that comes out of the factory with Windows preinstalled. That would be a very very bad thing.
Unfortunately both for Intel and AMD you don't have choices these days. I'm hoping someone develops a processor based on the RISCV architecture (a free architecture that doesn't include that shit) to be used in a computer entirely under the control of the user (hardware and software) and not the corporation that makes it.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#49This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…
A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.
IIRC, in Intel's case, the chipset has the vendor keys burned into it. This is not an issue, as the chipset is not a part you would remove from the board and use elsewhere.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#50There are a couple of issues I see with this. First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server. But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually h…
Nobody is going to care until this happens.