The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…
>malware like the Intel managament engine The code is not malicious please do not call it malware. Your computer already has dozens of other chips running proprietary software on them. It's just a normal part of PC components except since a CPU doesn't have a board the chip is built right in.
Lenovo vendor locking Ryzen CPUs with AMD PSB
151–160 of 234 posts
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#152This different article from STH explains what the AMD PSB is, without having to watch a video: https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-... > An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors…
> OEM who trusts only their own cryptographically signed BIOS code to run on their platforms It's not their platform after they sell it. We should resist this trend of referring to items as still belonging to their manufacturers, legitimizing their control over them, while we are reduced to mere users, paying for items but not owning them. Let's see how it sounds: > An OEM who wants to restrict their customers from s…
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#153The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…
That exists for the POWER architecture, but unfortunately those cpus are way behind x86 in speed and efficency, at least so far. I expect RISCV will be the same way for quite some time. Maybe someday...
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#154Earlier quoted context omitted.
The good news is the main manufacturers of RISC-V are Chinese vendors that allow complete access to low level processor details. They generally don't lock down their products at all.
Bad news is that US doesn't want to have anything with them.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#155Earlier quoted context omitted.
The good news is the main manufacturers of RISC-V are Chinese vendors that allow complete access to low level processor details. They generally don't lock down their products at all.
Bad news is that US doesn't want to have anything with them.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#156The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…
> It should be considered malware like the Intel managament engine and thus refused by users. Well, that clearly didn’t happen with ME. Intel’s market share gradually grew for the decade after ME was introduced.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#157Earlier quoted context omitted.
> The motivation from Lenovo's customer perspective is theoretically the customer knows this was the processor intended for the machine by Lenovo and nobody swapped it out in between the Lenovo factory and the customer's hands. Except that it works the other way. You can put a generic retail processor in the machine -- which will then ruin it by locking it to that vendor. No customer benefit exists.
> which will then ruin it by locking it to that vendor. Only if they click yes. https://twitter.com/FedsAgainstGunS/status/14734795248054927...
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#158Earlier quoted context omitted.
Bad news is that US doesn't want to have anything with them.
At this point, their government has completely undermined foreign confidence in their semiconductor industry. I would be careful to avoid any processors from there, because the chance that it contains a backdoor is just too great to risk. Even if that is only a perceived risk and not a real one. American propaganda in recent years clearly set out to reach this new status quo, and it’s probably all smoke and little to…
Anyone that wants to be 100% sure of the supply chain has to move away from globalization.
Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#159Re: Lenovo vendor locking Ryzen CPUs with AMD PSB
#160Earlier quoted context omitted.
This is very feel good but falls short of making an actual point. > The hypothetical homogeneous group 'they' you refer to doesn't exist They do exist. Making wrong statements with conviction doesn't make it true. You can look Chromebook sales figures, you can look at the best selling laptops at major retailers, you can look at what's driving record laptop sales, look at price points that are soaring, look at the mob…
Huh? I like your ideas, but I'm not painting. I'm saying "don't paint". If you think of it like a nice dividing line through the people who think stuff can change and the people who don't, the folks on the line are 'on the fence'. You see? If you can convince a few of them (not large swathes of them, just a few), then the line shifts. If we all do that, we can change a lot of minds for good! You get what I mean? So y…
Instead of trying to act like most people will ever care about locked bootloaders and PSB style co-processors, why don't we accept that they don't, they won't, and see what can happen from there?
An example of that is looking at it from a national security perspective. If you can paint it as a vulnerability to the tech industry you could see movement without the sisyphean task of convincing people that this stuff matters in their day-to-day lives