Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

231–234 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#231

There are a couple of issues I see with this. First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server. But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually h…

> because you could still swap out the CPU

No you can't. AMD builds the TPM in to the CPU, with AMD's encrypted memory feature (SEV), in theory you do not have to trust the data center an all.

The CPU boots, loads a verified firmware using PSB, initializes a safe environment in SEV, your entire boot procedure and data is encrypted and safe using FDE and SEV keys stored in the TPM using PCR's.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#232
post #90

There are a couple of issues I see with this. First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server. But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually h…

Good analysis. My question is wouldn't it be both more secure and more user friendly to burn the BIOS signing public keys into the motherboard chipset instead of the CPU?

Most people here don't seem to understand the entire point of this is to stop hardware tampering.

The goal of AMD's SEV and other features is that the only way to compromise the system is to tamper the wires between the CPU die and the IO die, that all data going outside the CPU die is encrypted, an extra hardware TPM chip module let you MITM the keys being sent to the CPU, having the keys stored in the CPU using fTPM, and never plaintext / keys leave or enter the CPU via PCIe or memory bus.

the "chipset" is literally just a PCIe/USB multiplexer these days, the CPU has no access to external hardware until after the firmware has loaded, the firmware has routines for turning on the memory and memory controller, PCIe etc, I don't think people understand just how utterly useless the CPU is without the firmware.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#233
post #53

Earlier quoted context omitted.

locking: At least some AMD CPUs (EPYC, TR PRO, Ryzen Pro) can have cryptographic keys burned into the silicon by the BIOS (Dell and Lenovo do that) Once a CPU has those keys burned into it, it is locked to motherboards of this specific vendor, because other motherboards don't have a BIOS that is signed with the cryptographic key that was burned in. PSB: Platform Security Boot PSP: Platform Security Processor (a CPU i…

what advantage does locking a CPU to a specific vendor give the vendor?

The point of locking the CPU to a specific vendor is to reduce the trusted user base in the cloud.

Currently you have to trust AMD, the Vendor, and the data center with your data.

The goal of verification of the firmware at such a low level is to eliminate tampering by the data center.

Having another feature like SEV (encrypted memory) combined with this lets you create a secure remote box that is fully encrypted at a very early stage in the boot process.

This reduces the chance of a malicious entity at a data center from tamping with the firmware to exfiltrate your keys.

Other people here are just ignorant and think it's being done purely for profit with no benefit to the end user.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#234
post #136

Earlier quoted context omitted.

Bad news is that US doesn't want to have anything with them.

You can still import them into the US en masse

Not if they break US patents (which is likely), or if the US puts more constraints on imports.
Post reply on HN