Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

61–70 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#62
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

> or potentially another model from the same manufacturer

This would allow an OEM/ODM to segment their offerings by having two or more sets of signing keys. "Oh sorry, that CPU only works in our entry-level offerings. You will need our enterprise-certified AMD CPU for your large server." "But it's the same socket!"

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#63
post #37

Earlier quoted context omitted.

A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.

As far as I know, Intel does exactly that (or at least allows vendors to do that, I think HP does that) IIRC, in Intel's case, the chipset has the vendor keys burned into it. This is not an issue, as the chipset is not a part you would remove from the board and use elsewhere.

Intel’s or AMD’s assistance is not needed at all. There is a rather boring flash chip connected by SPI to the CPU and/or PCH. One could interpose a microcontroller that verifies whatever it pleases on that SPI link.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#65
post #53

Earlier quoted context omitted.

locking: At least some AMD CPUs (EPYC, TR PRO, Ryzen Pro) can have cryptographic keys burned into the silicon by the BIOS (Dell and Lenovo do that) Once a CPU has those keys burned into it, it is locked to motherboards of this specific vendor, because other motherboards don't have a BIOS that is signed with the cryptographic key that was burned in. PSB: Platform Security Boot PSP: Platform Security Processor (a CPU i…

what advantage does locking a CPU to a specific vendor give the vendor?

Customers often want to upgrade the processors in their servers.

Someone bought some Dell servers with 32-core processors. They upgrade to 64-core processors and have the old 32-core processors. You'd like to buy them to upgrade your servers which have 16-core processors. Sorry, even though the chips are otherwise completely identical, theirs came from a Dell and you have a Lenovo. But hey, you can buy the processors directly from Lenovo for only three times as much money.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#66

Earlier quoted context omitted.

The feature was implemented in 2017 the only vendors that are using it are lenovo and dell. With lenovo being the only one using it on lower tier cpus than epyc.

Was it OEMs that asked for the feature or did three letter agencies pay AMD and Intel to back door all CPUs?

Perhaps not to back-door them, but to ensure when they (the government agencies) buy from Dell that the supply chain is intact and the BIOS hasn't been tampered with during shipping by a foreign agency. Like the NSA did to Cisco routers destined for international customers.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#68

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

> It should be considered malware like the Intel managament engine and thus refused by users.

Well, that clearly didn’t happen with ME. Intel’s market share gradually grew for the decade after ME was introduced.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#69
post #58

Earlier quoted context omitted.

Well its only a question of time before someone starts targeting the Intel vPro Management Engine and AMD PSB to alter CPU abilities using variations of code like that found on Github below. https://github.com/mostav02/Remove_IntelME_FPT https://github.com/rootkovska/x86_harmful/blob/master/x86_ha... https://github.com/corna/me_cleaner/blob/master/me_cleaner.p...

These would only help the power users, not the remaining 99%.

Trusted computing environments only hurt 1% of the users anyways.

We live in a world where people talk about Thinkpads vs Macbook Pros, but for 99% of the world laptops are appliances they buy like we'd buy a toaster.

They don't care that they can't run Linux, if anything onerous code signing requirements ala mobile devices would be great for the safety of their devices with minimal effects on what they can do.

-

I'm not saying I want the market for power users to die, I'm one of them after all, but I also feel like these conversations on HN are often disconnected from the reality most people live in...

This isn't really a "they don't know better so they don't complain", this is a "even if they knew better they wouldn't complain"

Post reply on HN