Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

171–180 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#171
post #5

All in the name of "security" of course.

It's been around a decade since Secure Boot first appeared and I remember well the opposition that had, along with a rallying cry based on the infamous Franklin quote. Unfortunately many of the opposition either accepted it or even defected, but the more this "security" stuff appears, the more I like that quote. It's succinct and gets the sentiment across very well.

Secure Boot is really quite separate from AMD PSB and actually does provide protection against certain attacks, no need for the double quotes. It's fortunate, not unfortunate, that we've gone past such irrational opposition to a reasonable extent.

Irrational opposition like that makes it much harder to talk about what's actually important, such as PSB/PSP, without getting lumped together with the tinfoil crowd.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#172
post #27

Earlier quoted context omitted.

Notably this seems to happen to CPUs that you might purchase yourself, which seems like a huge liability. If you somehow burn a $1000 CPU on a shitty mobo I can't see most people eating that.

My first thought was, is it really a big deal to do that to your laptop's cpu? Then I saw that they're doing this to desktops. My next thought was, people buy pre-built desktops still? Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.

You think businesses have some computer janitor working for them that puts together heckin epic artisanal gaming rigs? lol

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#174

Earlier quoted context omitted.

You're not wrong, but what's the motivation? With x86, backdoors and coprocessors were able to be added because both AMD and Intel were pretty much the only players in the ISA. Since they were effectively the only license-holders (and American multinational companies at that), the government had no problem forcing them to both add IME/PSP. With RISC-V, there is pretty much no such obligation. It's an open spec, there…

As others have pointed out the ISA has nothing to do with this. Intel could start building RISC-V CPUs with ME type technology tomorrow. Sure you're open to buy RISC-V CPUs from China but how are you going to be certain that they have no backdoors?

> As others have pointed out the ISA has nothing to do with this. Intel could start building RISC-V CPUs with ME type technology tomorrow.

From a purely technical standpoint, I agree (and wouldn't put it past Intel either). My argument is that having an open ISA makes it easier for manufacturers to compete with each other, which in turn makes it harder for interested parties to pin down every CPU manufacturer and punch holes in their individual designs.

> Sure you're open to buy RISC-V CPUs from China but how are you going to be certain that they have no backdoors?

Pragmatically, you can't. My point though was more that open ISAs give us options to buy hardware that doesn't get designed domestically, which is the main enabler for companies like AMD, Intel and Apple, and moreover, the government. If one chip is confirmed to be vulnerable in some way, you'll have legitimate competitors to choose from.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#176
post #38

Earlier quoted context omitted.

> OEM who trusts only their own cryptographically signed BIOS code to run on their platforms It's not their platform after they sell it. We should resist this trend of referring to items as still belonging to their manufacturers, legitimizing their control over them, while we are reduced to mere users, paying for items but not owning them. Let's see how it sounds: > An OEM who wants to restrict their customers from s…

It is the OEM's product. They are selling the BIOS, motherboard, and CPU as a single unit, along with a bunch of other stuff. If you wanted individual pieces, then buy individual pieces. Why are you even shopping for these products if you had any intention of ever dealing with in-socket CPU upgrades or parting it out second hand?

Most of us aren't merchants we as a society aren't obliged to let you do business save on our terms. If they think they can get more favorable terms elsewhere they can very well sell locked down elsewhere. This is a trend we ought to have shut down 20 years ago and we should darn well shut down now.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#177

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

We'll never be truly free until we can make our computers at home just like we can make our own software.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#178

Quoted post unavailable.

Are there any that are not manufactured in China?

Some models sold in Japan by Fujitsu/NEC/Lenovo/Vaio/Panasonic/HP are assembled in Japan. Lenovo acquired NEC and Fujitsu so they share factory. HP is interesting case. Some NEC/Vaio/Panasonic's laptop motherboard is also made in Japan.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#179
post #168

Earlier quoted context omitted.

You said it: it prevents you from booting a custom firmware. If the manufacturer decides to lock down the stock firmware for only booting Windows (something that is not absurd and some manufacturers already attempted in the past, and keep in mind that Microsoft is requiring TPM and secure boot with Windows 11) you are basically screwed. You can't boot Linux with the stock firmware and you can't change the system firm…

A computer that requires the firmware to be replaced to boot Linux is already at the point where 99% of users are just not going to install Linux (I've personally ported Coreboot to two of my laptops, and even I would never buy hardware that required me to do that before I could run Linux). And, well, you may well have never heard of attacks that would be mitigated by these technologies, but I have. Firmware-based at…

> And, well, you may well have never heard of attacks that would be mitigated by these technologies, but I have. Firmware-based attacks have existed for over a decade

This is a pure cash grab by Lenovo and AMD, not about mitigating attacks.

If this were about platform security for the benefit of the owner, it would not be permanent, nor enabled by default. All this does is create more e-waste and nuke resale value for Lenovo systems and Ryzen CPUs.

Lenovo has been increasingly slimy for years now (I guess everyone forgets that they've been caught distributing spyware in their products multiple times?) and this is just yet another stop on the road.

I hope Lenovo and AMD both get their asses sued.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#180
post #151

Earlier quoted context omitted.

>malware like the Intel managament engine The code is not malicious please do not call it malware. Your computer already has dozens of other chips running proprietary software on them. It's just a normal part of PC components except since a CPU doesn't have a board the chip is built right in.

Seems like you are not aware of Intel ME past vulnerabilities.

That would imply that basically every single piece of software ever made is malware.
Post reply on HN