Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

151–160 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#151

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

>malware like the Intel managament engine The code is not malicious please do not call it malware. Your computer already has dozens of other chips running proprietary software on them. It's just a normal part of PC components except since a CPU doesn't have a board the chip is built right in.

Seems like you are not aware of Intel ME past vulnerabilities.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#152
post #38
post #21

This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…

> OEM who trusts only their own cryptographically signed BIOS code to run on their platforms It's not their platform after they sell it. We should resist this trend of referring to items as still belonging to their manufacturers, legitimizing their control over them, while we are reduced to mere users, paying for items but not owning them. Let's see how it sounds: > An OEM who wants to restrict their customers from s…

It is the OEM's product. They are selling the BIOS, motherboard, and CPU as a single unit, along with a bunch of other stuff. If you wanted individual pieces, then buy individual pieces. Why are you even shopping for these products if you had any intention of ever dealing with in-socket CPU upgrades or parting it out second hand?

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#153

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

> Unfortunately both for Intel and AMD you don't have choices these days. I'm hoping someone develops a processor based on the RISCV architecture (a free architecture that doesn't include that shit) to be used in a computer entirely under the control of the user (hardware and software) and not the corporation that makes it.

That exists for the POWER architecture, but unfortunately those cpus are way behind x86 in speed and efficency, at least so far. I expect RISCV will be the same way for quite some time. Maybe someday...

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#154
post #136

Earlier quoted context omitted.

The good news is the main manufacturers of RISC-V are Chinese vendors that allow complete access to low level processor details. They generally don't lock down their products at all.

Bad news is that US doesn't want to have anything with them.

You can still import them into the US en masse

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#155
post #136

Earlier quoted context omitted.

The good news is the main manufacturers of RISC-V are Chinese vendors that allow complete access to low level processor details. They generally don't lock down their products at all.

Bad news is that US doesn't want to have anything with them.

At this point, their government has completely undermined foreign confidence in their semiconductor industry. I would be careful to avoid any processors from there, because the chance that it contains a backdoor is just too great to risk. Even if that is only a perceived risk and not a real one. American propaganda in recent years clearly set out to reach this new status quo, and it’s probably all smoke and little to no fire. But it worked. There are enough examples of China screwing over foreign companies to prove the risk could be real no matter your size (e.g. ARM China).

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#156

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

> It should be considered malware like the Intel managament engine and thus refused by users. Well, that clearly didn’t happen with ME. Intel’s market share gradually grew for the decade after ME was introduced.

Also it's not like there aren't legitimate uses for it. My workplace started taking advantage of it to help with remote management of all of our machines. It's useful to have another way in that doesn't rely on the OS being in a good state or even for the machine to be fully powered on.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#157
post #60

Earlier quoted context omitted.

> The motivation from Lenovo's customer perspective is theoretically the customer knows this was the processor intended for the machine by Lenovo and nobody swapped it out in between the Lenovo factory and the customer's hands. Except that it works the other way. You can put a generic retail processor in the machine -- which will then ruin it by locking it to that vendor. No customer benefit exists.

> which will then ruin it by locking it to that vendor. Only if they click yes. https://twitter.com/FedsAgainstGunS/status/14734795248054927...

Are you sure you want to permanently reduce the value of your CPU in exchange for no benefit of any kind?

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#158
post #136

Earlier quoted context omitted.

Bad news is that US doesn't want to have anything with them.

At this point, their government has completely undermined foreign confidence in their semiconductor industry. I would be careful to avoid any processors from there, because the chance that it contains a backdoor is just too great to risk. Even if that is only a perceived risk and not a real one. American propaganda in recent years clearly set out to reach this new status quo, and it’s probably all smoke and little to…

That applies to every foreign country actually.

Anyone that wants to be 100% sure of the supply chain has to move away from globalization.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#160

Earlier quoted context omitted.

This is very feel good but falls short of making an actual point. > The hypothetical homogeneous group 'they' you refer to doesn't exist They do exist. Making wrong statements with conviction doesn't make it true. You can look Chromebook sales figures, you can look at the best selling laptops at major retailers, you can look at what's driving record laptop sales, look at price points that are soaring, look at the mob…

Huh? I like your ideas, but I'm not painting. I'm saying "don't paint". If you think of it like a nice dividing line through the people who think stuff can change and the people who don't, the folks on the line are 'on the fence'. You see? If you can convince a few of them (not large swathes of them, just a few), then the line shifts. If we all do that, we can change a lot of minds for good! You get what I mean? So y…

I'm saying you're painting though, and I'm saying you can't talk like things are easy to get better and have a meaningful conversation.

Instead of trying to act like most people will ever care about locked bootloaders and PSB style co-processors, why don't we accept that they don't, they won't, and see what can happen from there?

An example of that is looking at it from a national security perspective. If you can paint it as a vulnerability to the tech industry you could see movement without the sisyphean task of convincing people that this stuff matters in their day-to-day lives

Post reply on HN