Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

111–120 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#111
post #86

Earlier quoted context omitted.

Watch the video, yes there is a prompt.

the prompt: https://twitter.com/FedsAgainstGunS/status/14734795248054927...

Thank you for the screencap, I wasn't about to watch a video to discover this.

1) It's WAY WAY too easy for someone to not really read this and just press Y to continue, like load setup defaults.

2) There should _not_ be a way of disabling the prompt (the popup even mentions you can do this.)

3) If ever there were a time for a simple math problem (like multiply two numbers and enter the result) to indicate a user had read and understood the prompt, this is it.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#113

Earlier quoted context omitted.

The hypothetical homogeneous group 'they' you refer to doesn't exist. It's billions of people and 'they' feel many ways. By painting with a common brush, you shut down discussions of what could be and encourage fence sitters to give up. Let's talk about why it's possible, easy to do, and how to do it. The more fence sitters you convince that things are possible, pushes the fence further and further towards the other…

I disagree. Market targeting, segmentation, and consumer preferences are real things which can be and are routinely measured.

Exactly the parent commercial it's point: market segments /can/ and do change sizes and their proportional relations. And more people are beginning to understand the importance of security for privacy in a world that is increasingly digital and dependent on information technology.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#114
Isn't Lenovo the problem? CPU vendors have to implement a secure enclave somehow to fulfill requirements from the content industry for quite some time now. But there never was a nefarious actor like Lenovo in this case to my knowledge.

I understand from this case that my reasonable course of action is to inform my (non-IT-focused) peers and friends that they should avoid Lenovo by explaining the reason behind it (your device is worth less, since you won't be able to install linux or a Mac Clone!) to them.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#115

Earlier quoted context omitted.

Or that commenter read and understood the description of how it works, and failed to see how it increases security in a meaningful way. I also struggle to think of a threat model that this protects against.

If something is not on your level of expertise you can always have a look for people that have the required level. It's just one search away. https://blog.cloudflare.com/anchoring-trust-a-hardware-secur...

I'm a security researcher. PSB as described there is orthogonal to the specific policy of tying the board to a specific CPU key, as you can tell from per CPU keys not being in the hardware root of trust as described by cloudflare. In fact you can swap the CPUs across boards from different ODMs in your most recent citation, since the root is an AMD key that then verifies the off chip ODM cert in flash.

I stand by my orignal statements.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#117

Earlier quoted context omitted.

You're not wrong, but what's the motivation? With x86, backdoors and coprocessors were able to be added because both AMD and Intel were pretty much the only players in the ISA. Since they were effectively the only license-holders (and American multinational companies at that), the government had no problem forcing them to both add IME/PSP. With RISC-V, there is pretty much no such obligation. It's an open spec, there…

> ...the government had no problem forcing them to both add IME/PSP. This is a false narrative, these management engines were added because large (corporate) customers of the major CPU vendors asked for them. Enterprise IT shops love stuff like this, anything to help them tame the unruly beast of asset inventory and management. This is the same reason things like iLO and DRAC exist, and they have all of the same type…

Why are management engines not delegated to professional/enterprise machines only then? Seems like an awful lot of money to waste putting specialized hardware into every machine you ship if only a fraction of the users will actually ever take advantage of it.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#118

Earlier quoted context omitted.

If something is not on your level of expertise you can always have a look for people that have the required level. It's just one search away. https://blog.cloudflare.com/anchoring-trust-a-hardware-secur...

I'm a security researcher. PSB as described there is orthogonal to the specific policy of tying the board to a specific CPU key, as you can tell from per CPU keys not being in the hardware root of trust as described by cloudflare. In fact you can swap the CPUs across boards from different ODMs in your most recent citation, since the root is an AMD key that then verifies the off chip ODM cert in flash. I stand by my o…

If you really think PSB doesn't provide any security benefit or "improves security in a meaningful way" you should do more security research.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#119

Earlier quoted context omitted.

The hypothetical homogeneous group 'they' you refer to doesn't exist. It's billions of people and 'they' feel many ways. By painting with a common brush, you shut down discussions of what could be and encourage fence sitters to give up. Let's talk about why it's possible, easy to do, and how to do it. The more fence sitters you convince that things are possible, pushes the fence further and further towards the other…

This is very feel good but falls short of making an actual point. > The hypothetical homogeneous group 'they' you refer to doesn't exist They do exist. Making wrong statements with conviction doesn't make it true. You can look Chromebook sales figures, you can look at the best selling laptops at major retailers, you can look at what's driving record laptop sales, look at price points that are soaring, look at the mob…

Huh? I like your ideas, but I'm not painting. I'm saying "don't paint". If you think of it like a nice dividing line through the people who think stuff can change and the people who don't, the folks on the line are 'on the fence'. You see? If you can convince a few of them (not large swathes of them, just a few), then the line shifts. If we all do that, we can change a lot of minds for good!

You get what I mean? So yeah, my recommendation is that we all talk like things are easy to make better, instead of saying, "too late its all over" because you'll encourage more people to try which I assume you agree is a good thing but if not, I guess to each their own.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#120
post #37
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

A much nicer solution would be a move the static root of trust off the CPU package. The motherboard’s EC could easily verify a BIOS signature before allowing boot with no CPU involvement whatsoever.

I think part of the motivation here is tying it in with the PSP and having the root of trust be the processor and not processor for some stuff and motherboard for others. For PSP related stuff it does make sense to centralize on AMD rather than having every vendor have their own implementation of some platform security standard. It's dumb to let motherboards effectively brick a CPU but there reasonably could be a way to have the root of trust on the CPU and extend that to firmware signatures so you could remotely attest BIOS versions, etc.

I've mentioned this elsewhere but they could have just added some way of writing this signature out of band or allow bypassing it via a solder bridge on the top of the package like how SPD works on memory but require a separate interface for writing to it. Requiring a $10 I2C to USB adapter to change the key is not that onerous and it would be simple enough for OEMs to flash whatever they wanted on it and it could still be cleared for resale. For protecting against an APT doing shipment interdiction attacks quite frankly that sounds like a bunch of B.S. as all locking the key on the processor does is require the processor to be swapped out during an attack as well. If someone is going through the effort to intercept hardware in transit to flash custom malicious firmware on it, the cost of swapping the processor as well is not that extreme.

If they're going to keep the strategy of blowing fuses on the CPU die then AMD should be the ones doing it and they should make a vendor specific SKU so that trying to figure out if a CPU is vendor locked or not isn't such a minefield.

Post reply on HN