Someone still buys Lenovo?
Lenovo vendor locking Ryzen CPUs with AMD PSB
61–70 of 234 posts
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#62This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…
This would allow an OEM/ODM to segment their offerings by having two or more sets of signing keys. "Oh sorry, that CPU only works in our entry-level offerings. You will need our enterprise-certified AMD CPU for your large server." "But it's the same socket!"
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#63Earlier quoted context omitted.
A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.
As far as I know, Intel does exactly that (or at least allows vendors to do that, I think HP does that) IIRC, in Intel's case, the chipset has the vendor keys burned into it. This is not an issue, as the chipset is not a part you would remove from the board and use elsewhere.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#64Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#65Earlier quoted context omitted.
locking: At least some AMD CPUs (EPYC, TR PRO, Ryzen Pro) can have cryptographic keys burned into the silicon by the BIOS (Dell and Lenovo do that) Once a CPU has those keys burned into it, it is locked to motherboards of this specific vendor, because other motherboards don't have a BIOS that is signed with the cryptographic key that was burned in. PSB: Platform Security Boot PSP: Platform Security Processor (a CPU i…
what advantage does locking a CPU to a specific vendor give the vendor?
Someone bought some Dell servers with 32-core processors. They upgrade to 64-core processors and have the old 32-core processors. You'd like to buy them to upgrade your servers which have 16-core processors. Sorry, even though the chips are otherwise completely identical, theirs came from a Dell and you have a Lenovo. But hey, you can buy the processors directly from Lenovo for only three times as much money.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#66Earlier quoted context omitted.
The feature was implemented in 2017 the only vendors that are using it are lenovo and dell. With lenovo being the only one using it on lower tier cpus than epyc.
Was it OEMs that asked for the feature or did three letter agencies pay AMD and Intel to back door all CPUs?
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#67Someone still buys Lenovo?
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#68The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…
Well, that clearly didn’t happen with ME. Intel’s market share gradually grew for the decade after ME was introduced.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#69Earlier quoted context omitted.
Well its only a question of time before someone starts targeting the Intel vPro Management Engine and AMD PSB to alter CPU abilities using variations of code like that found on Github below. https://github.com/mostav02/Remove_IntelME_FPT https://github.com/rootkovska/x86_harmful/blob/master/x86_ha... https://github.com/corna/me_cleaner/blob/master/me_cleaner.p...
These would only help the power users, not the remaining 99%.
We live in a world where people talk about Thinkpads vs Macbook Pros, but for 99% of the world laptops are appliances they buy like we'd buy a toaster.
They don't care that they can't run Linux, if anything onerous code signing requirements ala mobile devices would be great for the safety of their devices with minimal effects on what they can do.
-
I'm not saying I want the market for power users to die, I'm one of them after all, but I also feel like these conversations on HN are often disconnected from the reality most people live in...
This isn't really a "they don't know better so they don't complain", this is a "even if they knew better they wouldn't complain"
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#70All in the name of "security" of course.