Could it be AMDs doing behind the scenes? I don't see the motivation for Lenovo here but I do see AMD asking vendors to do this to prevent OEM CPUs completing with retail CPUs.
The feature was implemented in 2017 the only vendors that are using it are lenovo and dell. With lenovo being the only one using it on lower tier cpus than epyc.
Lenovo vendor locking Ryzen CPUs with AMD PSB
51–60 of 234 posts
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#52If you buy a Lenovo, then the CPU dies and you replace it with an unlocked retail one, will the motherboard blow the fuses in the new one and lock it too as soon as you power it up?
I think thats what the previous gen did, so most likely yes.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#53I'm not up on CPU terminology. I read the article and I don't know what this means. What is "locking" in this context? What is the "AMD PSB" ?
locking: At least some AMD CPUs (EPYC, TR PRO, Ryzen Pro) can have cryptographic keys burned into the silicon by the BIOS (Dell and Lenovo do that) Once a CPU has those keys burned into it, it is locked to motherboards of this specific vendor, because other motherboards don't have a BIOS that is signed with the cryptographic key that was burned in. PSB: Platform Security Boot PSP: Platform Security Processor (a CPU i…
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#54Earlier quoted context omitted.
A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.
As far as I know, Intel does exactly that (or at least allows vendors to do that, I think HP does that) IIRC, in Intel's case, the chipset has the vendor keys burned into it. This is not an issue, as the chipset is not a part you would remove from the board and use elsewhere.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#55Earlier quoted context omitted.
The feature was implemented in 2017 the only vendors that are using it are lenovo and dell. With lenovo being the only one using it on lower tier cpus than epyc.
Was it OEMs that asked for the feature or did three letter agencies pay AMD and Intel to back door all CPUs?
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#56Earlier quoted context omitted.
Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.
My first thought was, is it really a big deal to do that to your laptop's cpu? Then I saw that they're doing this to desktops. My next thought was, people buy pre-built desktops still? Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#57The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#58The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…
Well its only a question of time before someone starts targeting the Intel vPro Management Engine and AMD PSB to alter CPU abilities using variations of code like that found on Github below. https://github.com/mostav02/Remove_IntelME_FPT https://github.com/rootkovska/x86_harmful/blob/master/x86_ha... https://github.com/corna/me_cleaner/blob/master/me_cleaner.p...
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#59Earlier quoted context omitted.
Was it OEMs that asked for the feature or did three letter agencies pay AMD and Intel to back door all CPUs?
CPUs being backdoored is orthogonal to this.
It’s what I’d do..,
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#60Could it be AMDs doing behind the scenes? I don't see the motivation for Lenovo here but I do see AMD asking vendors to do this to prevent OEM CPUs completing with retail CPUs.
The motivation from Lenovo's customer perspective is theoretically the customer knows this was the processor intended for the machine by Lenovo and nobody swapped it out in between the Lenovo factory and the customer's hands. Of course, no system is perfect so it's not a full guarantee and also there's the impact to the secondary market. But if you're an enterprise leasing these machines you don't care about the seco…
Except that it works the other way. You can put a generic retail processor in the machine -- which will then ruin it by locking it to that vendor.
No customer benefit exists.