Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

81–90 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#81

Earlier quoted context omitted.

Trusted computing environments only hurt 1% of the users anyways. We live in a world where people talk about Thinkpads vs Macbook Pros, but for 99% of the world laptops are appliances they buy like we'd buy a toaster. They don't care that they can't run Linux, if anything onerous code signing requirements ala mobile devices would be great for the safety of their devices with minimal effects on what they can do. - I'm…

The hypothetical homogeneous group 'they' you refer to doesn't exist. It's billions of people and 'they' feel many ways. By painting with a common brush, you shut down discussions of what could be and encourage fence sitters to give up. Let's talk about why it's possible, easy to do, and how to do it. The more fence sitters you convince that things are possible, pushes the fence further and further towards the other…

I disagree. Market targeting, segmentation, and consumer preferences are real things which can be and are routinely measured.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#82

Earlier quoted context omitted.

The hypothetical homogeneous group 'they' you refer to doesn't exist. It's billions of people and 'they' feel many ways. By painting with a common brush, you shut down discussions of what could be and encourage fence sitters to give up. Let's talk about why it's possible, easy to do, and how to do it. The more fence sitters you convince that things are possible, pushes the fence further and further towards the other…

I disagree. Market targeting, segmentation, and consumer preferences are real things which can be and are routinely measured.

That's agreement, not disagreement.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#83
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

Thanks for the explanation, this is what I suspected but it wasn't made clear by the hysteria of the video because I really don't see the problem here. Most computers end up on the dump as one unit anyways. I've built a few computers in my time but never used an old CPU from one. And especially not one with that form factor that I probably buy as a wardrobe homelab purpose. I'd compare it to my Asus PN50 that does ha…

> I've built a few computers in my time but never used an old CPU from one.

I've routinely upgraded drives, graphics cards and memory to give an older system a new lease on life. Usually they're good for a couple of years after that. Essentially the only things remaining where motherboard, CPU and the power supply.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#84

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

> RISCV architecture (a free architecture that doesn't include that shit)

Surely you can't think the architecture itself is the differentiator. x86 didn't have all of this security 20 years ago, give engineers a few years of time to throw some locks on a risc-v chip and it'll be Enterprise Ready™ in no time.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#86
post #33

How is it not illegal to do this without at least first ASKING the user for confirmation? I'd be annoyed but find it 'merely anti-consumer' rather than 'intentional destruction of property' if the BIOS refused to finish POST without the user confirming that yes, they want to sacrifice this CPU and make it (p)owned by $CORP.

Watch the video, yes there is a prompt.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#87

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

Raptor CS are still making those Power9 workstations I think. Power9 is also a free architecture “without that shit”.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#88
post #73

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

> a free architecture that doesn't include that shit There is nothing stopping RISC-V SoC/CPU vendors from tacking it on.

You're not wrong, but what's the motivation? With x86, backdoors and coprocessors were able to be added because both AMD and Intel were pretty much the only players in the ISA. Since they were effectively the only license-holders (and American multinational companies at that), the government had no problem forcing them to both add IME/PSP.

With RISC-V, there is pretty much no such obligation. It's an open spec, there is no licensing fee and there isn't an obligation to add hardware susceptibilities. Chinese companies will (and are) manufacture chips like this at the lowest cost possible, likely eschewing any black-box m53s running Minix that you'd find on an American CPU. It also opens the possibility for more bespoke chip designs (as it's a modular ISA), and hopefully dividing the market between security-conscious products and consumer ones will stop all devices from being digitally wiretapped.

It's all speculation right now, but it's highly unlikely that RISC-V will be pozzed in the same way x86 or even modern ARM clusters are. There's too much competition, too much money to be made, and too few incentives. Suffice to say, you're probably going to hear the three-letter agencies complaining about "unsafe Chinese chips" soon or something equally stupid.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#89
post #33

How is it not illegal to do this without at least first ASKING the user for confirmation? I'd be annoyed but find it 'merely anti-consumer' rather than 'intentional destruction of property' if the BIOS refused to finish POST without the user confirming that yes, they want to sacrifice this CPU and make it (p)owned by $CORP.

Because this is on the marketing page or spec sheet that you see before you buy the product, thus it being bound to $manufacturer's board is a feature. It's the same reason Apple execs haven't been thrown in jail for selling iPhones that only run iOS.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#90

There are a couple of issues I see with this. First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server. But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually h…

Good analysis. My question is wouldn't it be both more secure and more user friendly to burn the BIOS signing public keys into the motherboard chipset instead of the CPU?
Post reply on HN