Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

41–50 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#41
post #27

Earlier quoted context omitted.

Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.

My first thought was, is it really a big deal to do that to your laptop's cpu? Then I saw that they're doing this to desktops. My next thought was, people buy pre-built desktops still? Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.

Maybe not the worst track record but they have made other terrible choices...

https://en.m.wikipedia.org/wiki/Superfish

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#43
There are a couple of issues I see with this.

First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server.

But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually have a remote KVM feature, so you could e.g. boot the OS into recovery mode)

It does not prevent any other attacks, because you could still swap out the CPU. The servers usually just quietly burn the CPUs, so you wouldn't notice if the CPUs were replaced by an attacker.

Second, this produces a lot of unnecessary e-waste. About 99% of all hardware (except HDDS) from datacenters is sold on the second hand market. Locked CPUs are essentially worthlese, especially if buyers or sellers don't know and throw the CPU away because they think it's defective.

Third, this opens up a MASSIVE attack surface. Imagine if somebody finds a bug im the PSP (Platform Security Processor, a CPU inside the CPU that handles the locking thing amon g other things) and is able to burn arbitrary keys into the CPU. The attacker would randomly generate a key and burn them into the CPU. You could permanently kill an entire datacenter with that within seconds.

Or if somebody manages to write a malicious BIOS version and flash it to servers which usually don't have a locked BIOS. This BIOS version would also burn a random key into the CPU with the same result: You can easily permanently destroy an entire datacenter.

I think this is just AMD's greediness again in the cloak of "improving security"

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#45

Quoted post unavailable.

Are there any that are not manufactured in China?

Maybe Fujitsu?

https://indianexpress.com/article/technology/tech-news-techn...

Of course, I assume lots of components for those are made in China.

Samsung might make in South Korea? Asus in Taiwan?

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#47
post #27

Earlier quoted context omitted.

Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.

My first thought was, is it really a big deal to do that to your laptop's cpu? Then I saw that they're doing this to desktops. My next thought was, people buy pre-built desktops still? Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.

> My next thought was, people buy pre-built desktops still?

If you are enthusiast and need a one or two desktops, then probably not. If you need to procure several hundred of them every few months, then probably yes.

What this definitely will do is to affect the market price of these desktops once the lease (or depreciation time) runs out and owner will try to unload them on second hand market.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#48
The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user.

The AMD PSB can also be used to lock down a processor to enforce secure boot and thus don't let you run an unsigned operating system, i.e. no longer allowing you to run Linux on your machine that comes out of the factory with Windows preinstalled. That would be a very very bad thing.

Unfortunately both for Intel and AMD you don't have choices these days. I'm hoping someone develops a processor based on the RISCV architecture (a free architecture that doesn't include that shit) to be used in a computer entirely under the control of the user (hardware and software) and not the corporation that makes it.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#49
post #37
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.

As far as I know, Intel does exactly that (or at least allows vendors to do that, I think HP does that)

IIRC, in Intel's case, the chipset has the vendor keys burned into it. This is not an issue, as the chipset is not a part you would remove from the board and use elsewhere.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#50

There are a couple of issues I see with this. First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server. But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually h…

“ You could permanently kill an entire datacenter with that within seconds.”

Nobody is going to care until this happens.

Post reply on HN