Live data from Hacker News

AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

extremetech.com

61–70 of 88 posts

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#61
I really don't like the idea of having field-programmable OTP memories in microprocessors. This shouldn't be possible, there should be a physical VPP pin (as in MediaTek SoCs), if you don't supply power to this then no fuses are blowable. Otherwise we're going to have ransomware physically brick CPUs if you do not pay up on time.

There's even worse possibilities, I think some hardware has ~1KB of executable OTP which can be programmed in that manner - so it may just be possible to implement some kind of backdoor that resides in the physical CPU. Maybe something only a state-level attacker could do.

For example, it could prevent CPU side-channel mitigations from ever working, somehow, e.g. by repeatedly writing to a private internal register to stealthily keep the CPU vulnerable. And few would ever know about it, because it's hidden in an on-chip security processor.

Personally I utterly hate all AMD chips which have a Platform Security Processor. Locking down your own property to prevent you from accessing it should be illegal.

There is a full Trustronic Trusted Execution Environment running in there, on both GPU and CPUs, I believe. For example the TEE firmware blob for a radeon GPU on Linux is "/lib/firmware/amdgpu/psp_13_0_7_sos.bin", with "sos" meaning Secure Operating System. And some of these firmware files are encrypted, so you can't reverse engineer them.

The moment some ARM SoC company such as Rockchip comes up with a chip that's within an order of magnitude in performance, then my AMD chip (EPYC) is going in the bin. After being smashed to pieces with a hammer, live on YouTube, with an explaination why. That might get AMD marketing to pay attention.

Update: Ampere Altra CPUs have seperate power pins for blowing eFuses, you can find it in the public datasheet here[1], on page 55, the supply pins are EFUSE_MFG_VDDQ1P8 and EFUSE_PCP_VDDQ1P8. It says tie to GND if unneeded.

Also they have a public datasheet for the chip. I wonder if we can buy unfused CPUs without secure boot enabled? Or is that the default state of the chip?

Could someone design a simple and cheap open-source motherboard for one of these processors, it's only a matter of time before the chips start turning up on Ebay? We will need more documentation from Ampere than just the datasheet, of course.

1. https://uawartifacts.blob.core.windows.net/upload-files/Altr...

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#62
post #57
post #54

Earlier quoted context omitted.

It mostly just cripples the secondary market for used server hardware.

I dont see the economics of splitting servers for parts. Aside from pulling drives for shredding, servers are mostly sold as pulled on the aftermarket

"I don't see" != "Does not exists"

Refurb server parts market is more than alive, especially when a 5 year old server CPU is almost as good as a new one, but for $100 instead of $5000.

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#64
post #57
post #54

Earlier quoted context omitted.

It mostly just cripples the secondary market for used server hardware.

I dont see the economics of splitting servers for parts. Aside from pulling drives for shredding, servers are mostly sold as pulled on the aftermarket

Not every company is willing to end of life perfectly good servers every five years either. Our fleet is mainly Frankensteined secondary servers with a pile of spares for repair.

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#65
post #12

For those who just read the title: the "fuse" doesn't stop the cpu from working, it's just a flag for AMD support to know that the chip has been overclocked and this might invalidate the warranty.

On a related note, AMD's EPYC CPUs have eFuses that enforce a vendor lock. This means you can't transfer an EPYC CPU from, say, a Dell server to a Lenovo server. https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-...

This is also true of the Threadripper Pro 3000/5000 CPU's (likely the 7000 as well, but I can't state that with certainty). Perhaps not surprising since they are basically EPYC's, but worth noting.

I was an early adopter and got bitten by it via a Lenovo.

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#66
post #61

I really don't like the idea of having field-programmable OTP memories in microprocessors. This shouldn't be possible, there should be a physical VPP pin (as in MediaTek SoCs), if you don't supply power to this then no fuses are blowable. Otherwise we're going to have ransomware physically brick CPUs if you do not pay up on time. There's even worse possibilities, I think some hardware has ~1KB of executable OTP which…

I'm guessing that vulnerabilities tied to ongoing manufacturer control (CPUs, cars, Polish locomotives, etc.) will continue until a widespread attack turns public opinion.

And I fear that even then, lobbyists and/or intelligence agencies will neuter any response.

Shoot, now I'm just making myself depressed.

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#67
post #12

Earlier quoted context omitted.

On a related note, AMD's EPYC CPUs have eFuses that enforce a vendor lock. This means you can't transfer an EPYC CPU from, say, a Dell server to a Lenovo server. https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-...

Smh this is ridiculous. You literally bought the hardware...

This practice should be made illegal, if it's not already.

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#68
post #61

I really don't like the idea of having field-programmable OTP memories in microprocessors. This shouldn't be possible, there should be a physical VPP pin (as in MediaTek SoCs), if you don't supply power to this then no fuses are blowable. Otherwise we're going to have ransomware physically brick CPUs if you do not pay up on time. There's even worse possibilities, I think some hardware has ~1KB of executable OTP which…

I'm guessing that vulnerabilities tied to ongoing manufacturer control (CPUs, cars, Polish locomotives, etc.) will continue until a widespread attack turns public opinion. And I fear that even then, lobbyists and/or intelligence agencies will neuter any response. Shoot, now I'm just making myself depressed.

That's why we need open source chips, the same restrictions we had with proprietary software are now coming to hardware. Plenty of interesting things to do with FPGAs, and the community is even in the early stages of developing open source FPGAs now.

It was AMD with their PSP that pushed me into FPGAs and creating open source hardware, now that everything is getting locked down.

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#69
post #57
post #54

Earlier quoted context omitted.

It mostly just cripples the secondary market for used server hardware.

I dont see the economics of splitting servers for parts. Aside from pulling drives for shredding, servers are mostly sold as pulled on the aftermarket

however shocking you may find it, typing “epyc cpu” into eBay will nonetheless produce quite a few results.

this used to be even bigger in the Xeon days. Being able to drop in a $50 upgrade to x99 and get the 2-3 best chip in socket owns actually. X99 isn't bad if you've got a 18-core chip running at 3.8 ghz all-core (with all-core turbo enhancement), and you can address 256GB of memory in a consumer board with dirt-cheap 32GB RDIMM sticks (they are basically under $20 now) since many X99 boards also support RDIMM (including on consumer cpus).

Like let's not cheer literal e-waste here. Secondary users keep hardware out of landfills, a lot of those customers have existing systems they want to upgrade or want to build using whitebox brands like supermicro/asrock rack, the EU absolutely needs to tamp down on this practice.

The most silly part is, how does locking it to the brand do anything anyway? If you locked the CPU to the board then sure, that makes sense, but the threat model here is an employee is stealing your CPUs and swapping them out with something cheaper, and this makes them... find another lenovo or dell branded CPU to match it with? and with PSP allowing secure manipulation of non-volatile storage, there is zero reason to make this a permanent fuse, why shouldn't you allow this to also be unlocked when it's time for disposal? like if you want to prevent the "evil maid" attack you would want it to be both more tightly locked to the board and also unlockable so it can be serviced.

(even if you don't want to trust non-volatile storage, you can also make "pseudo-non-volatile" out of plain old e-fuses. even number of fuses blown = unlocked, odd = locked. being able to lock and unlock say 128 times is plenty, in practice.)

And ironically the e-waste this produces (brand-locked chips) actually makes the cost of these evil-maid swapping attacks even cheaper, because nobody wants them on the secondary market, the cheapest platform-locked naples chips are probably already absolutely worthless because nobody wants naples to begin with, let alone brand-locked naples.

it so very obviously is narrowly targeted at making sure the secondary market is a confusing mess that buyers want to avoid. Creating e-waste to sell more chips. Again, the EU really needs to step in, it is noxious, they should even be forced to release a firmware update unlocking existing chips (AMD is the root of trust and can do this).

Sadly Intel has also really cracked down on xeon secondary sales as well - starting with broadwell, xeons can't be used in consumer Z97 boards, and they went to the same thing on X299, as well as cracking down on unlocked multipliers on certain skus (1660v3 has it, among others) and all-core turbo enhancement with broadwell-EP. It would be nice if you could drop an epyc into your threadripper board, too, that's basically the modern equivalent of ye olde xeon ebay upgrade. On the other hand, there’s no surprises either - socket compatible cpus are socket compatible, your board may only work with consumer chips but it does work with all of them.

And frankly people are also underplaying the fact that AMD does this on consumer socket as well - consumers would benefit from having a bunch of cheap zen2/zen3 chips from old OEM systems in a year or two here, that would push prices down even farther.

There is also a general danger that if the systems don’t have any resale value anymore that they will be scrapped entirely instead of resold as either parts or a complete server. If the value of the server is nothing, nobody will bother re-using it. You’ve literally turned working parts into e-waste, nobody wants them anymore and it stops being economically viable to bother for the handful of people who do. Everyone benefits from reduced friction in a market.

Re: AMD's New Threadripper Chips Have a Hidden Fuse That Blows When Overclocking

#70

I don't know if overclocking pays off much these days. The chips are already taken close to limits with factory settings, so there's not much overclocking potential unless you use extreme cooling. I fondly remember the Core 2 Duo days when I overclocked my CPU with more than 50% using the stock cooler. It's nice to 50% performance for free, particularly when you are poor. I even remember overclocking an old laptop wi…

Frankly this is aimed more at XMP, where vendors routinely bump IMC voltage to get those swanky binned gaming kits onto the QVL. A ddr4-4800 kit obviously isn’t going to work on stock voltage with a memory controller rated at 3200, the gap is covered by increasing VCCIO and VCCSA a lot, and this results in quite a few chips with failed memory controllers over time.

Also, on AMD there is an extremely widespread culture of overclocking the fabric which again, can result in degradation over time (progressively lower clocks at a given voltage, or instability at a fixed clock). People very much still believe in the fairy-tale of “24/7 safe” overclocking - obviously the manufacturer has every incentive to certify the chip as fast as it’ll go, they set the limit at the 24/7 safe point already, but the gains are so potent that people tell themselves whatever they need to hear.

https://www.amd.com/en/legal/claims/gaming-details.html

AMD and intel have been very very clear for a very long time that this is not covered by warranty (see AMD GD-106/GD-112) but people have low key continued to do it and warranty the CPUs when they fail, because there wasn’t a way for AMD and intel to tell. And to be fair - AMD and intel have often muddled the waters by using these numbers in their benchmarks etc. But there remains a general sense of “if you didn’t turn on XMP you didn’t do the build right” and “XMP can’t hurt anything as long as you don’t increase the voltages” despite this already being done automatically by the board.

XMP absolutely does cause damage and I killed a 9900k with no other overclocking simply by enabling XMP on a fast kit. But consumers still don’t get the memo, they think it is only a problem if you instantly blow up the chip like the 7000 series at launch. XMP is widely viewed as safe and even something you're supposed to be doing.

Electromigration happens very quickly at 7nm and 5nm nodes, and people are not used to it, and it’s low key also a thing on 14nm and 10nm class too. But it is already something that CPUs have to be designed around and designed to detect and monitor and tolerate as part of the boost algorithm (that stability margin is also headroom the boost algorithm wants to exploit), they devote an enormous amount of effort to electromigration already. And the mismatch between that public understanding of the problem and the reality is causing a lot of warranty claims. You can see from enterprise fleets that CPUs don’t normally fail, yet every enthusiast knows someone who had a chip die “even without overclocking! I just enabled XMP!”. Of the failed CPUs getting returned for warranty, probably a plurality are memory overclocking failures. And this is only going to continue to get worse over time - 2.5D and 3D packaging are both progressively even more sensitive due to thermals, and have tighter requirements for voltage stability since they need to talk to the other dies at very low voltages (especially across heterogeneous dies with different metal stacks/totally different processes etc).

https://semiengineering.com/3d-ic-reliability-degrades-with-...

https://semiengineering.com/on-chip-power-distribution-model...

Post reply on HN