Live data from Hacker News

AMD silently removes memory encryption from consumer Ryzen CPUs

tomshardware.com

41–50 of 225 posts

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#41
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

Reminds me of that Seinfeld episode where George tries to move a Frogger arcade machine without powering it off in order to not lose his high score leaderboard.

https://youtu.be/5etwHVarNgI?t=256

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#43
post #30
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

Transparent communication would have been appreciated nonetheless. You have customers not just lawyers on the other side, it's not just about making sure you're legally covered.

Let me give you an analogy: If you e.g. figure out some undocumented endpoints for a REST API, which are intended for internal use only, and started using them, do you expect the developers to inform you about changes?

As far as AMD is concerned, this was never supported, nor documented. Now pulling the rug with a firmware update isn't a very nice thing to do, but maybe they've had some actual reason for that beyond "this shouldn't be enabled". Nobody should expect undocumented and unsupported features to just continue to work in perpetuity, simply because they did work at some point in the past.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#44
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

Many many people use consumer CPUs for gaming servers.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#45
post #33
post #26

Earlier quoted context omitted.

if anyone does it sneakily, there is alleged wrongdoing attached to it. I can imagine multiple scenarios like some well-known Israeli company "selling their software only to governments", paying quite amount of money for it, because they were unable to break this one.

> there is alleged wrongdoing attached to it Probably not from a legal perspective, but morally yes. Apple cause batterygate with good intentions but sneakily. Not being transparent is what shot them in the foot. AMD didn't learn anything or thinks this is small-time so no blowback (sadly they might be right).

> Apple cause batterygate with good intentions but sneakily.

Sure, the Apple's intentional performance degradation of older iPhones was caused by only good intentions, not a form of planned obsolescence in any way. How could it be?

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#46
post #35

I wonder what the additional power draw of these features would be. Parenthetically, I wonder often about the energy impact of all these HTTPS localhost links, and is there a point where defense-in-depth has to give way to other concerns? But yeah 95% of the consumer market don't care about this and it's only adding unnecessary costs

Consumers were always capable of disabling it themselves if they didn't need it. The performance impact seems to be ~3% on average, impact on power consumption is probably similar or less since any extra delay idling can destroy performance while not having as big impact on power consumption. https://www.phoronix.com/review/amd-memory-guard-ram-encrypt...

Any extra cost would be mostly due to power consumption and testing that the feature works (which they probably don't do for consumer skews anyway). The area of silicon used by the feature is probably negligible, from the manufacturing cost perspective it's cheaper to avoid any unnecessary design differences between skews.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#47
post #38
post #27

I had this enabled as it protects against RAMbleed/ECC errors, so it's not limited to physical attacks.

Are you sure? I thought it's just AES without any authentication.

Yes, it's AES with a tweak based on the physical address. It adds some protection from RowHammer and the like because flipping a bit in encrypted memory is catastrophic, while it can be done in a controlled manner if it's not encrypted.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#48
post #5
post #2

Any idea what's happening? This sounds _bad_.

> To be fair to AMD, there is no clear indication that the company ever publicly advertised TSME as a consumer Ryzen feature. A feature that was possibly accidentally enabled on consumer chips is now being disabled. I would guess that the number of owners of consumer chips who also relied on them for encryption is exceedingly small. The primary concern persists. The manufacturer has an exceptional amount of control o…

> A feature that was possibly accidentally enabled on consumer chips is now being disabled.

Bro what are you smoking? The highly paid and experienced engineers designing these chips could have "possibly enabled" the feature on consumer chips.

The chips were designed with the feature as it is cheaper to do everything right from the get go and disable functionality rather than design a less capable chip then tack on the feature afterwards, just as the consumer versions of Windows are the server versions with functionality removed.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#49
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

Many many people use consumer CPUs for gaming servers.

So reading between the lines, you're saying it's bad for AMD to disable undocumented features because people still might have bought them for those undocumented features, particularly for gaming servers?

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#50
post #4

If it can be silently removed was it a security feature? Whilst I hate companies paying engineers to make things worse just to segment their market; I am not really seeing this as an important feature outside the data-center? If an evil-maid has hardware access they hack the USB and/or PCI not the RAM surely?

Sneakily and silently removing a feature in a firmware revision is not acceptable, security or otherwise.

> Sneakily and silently removing a feature in a firmware revision is not acceptable

What if said feature was sneakily and silently added in the first place? Wouldn't it be acceptable to sneakily and silently removing it in the future then? Or regardless of if it was documented/announced or not, removing anything sneakily and silently is bad?

Post reply on HN