Live data from Hacker News

AMD silently removes memory encryption from consumer Ryzen CPUs

tomshardware.com

71–80 of 225 posts

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#71
post #68

I don't know how this works but does this mean if someone gained physical access to your locked running computer, they could gain access to your full encrypted drive and anything saved on disk? My reasoning there is if you used an encrypted drive, the decryption key you type when booting up would be stored in memory for the duration of that boot. This seems alarming because it means if someone broke into your living…

This feature was off by default in all the mobos I've seen.

It causes many stability issues, as to my experience.

The attack is sophisticated, Mr.Nobody, generally, should not worry about expensive cryogenic attacks - three letter guys would extract your key with a wrench.

I mean the change is bad - it undermines already damaged trust, but the "average Joe" is extremely unlikely to be affected directly.

There are many much cheaper ways to force you to give up your keys.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#72
post #28

Earlier quoted context omitted.

There was a patch called Tresor that did this, but I don't think it was updated for a long time. You have to store the encryption key in CPU registers and ensure it's not saved to RAM during task switching or power suspend operations. Tresor used x86-specific debug registers for it, but you could potentially use unused SIMD registers if you masked-off the CPUID bits for them and disabled them for access by user-space…

> You have to store the encryption key in CPU registers and ensure it's not saved to RAM during task switching or power suspend operations. Interesting insight. Any reason why the key can't be kept exclusively in the secure enclave / trusted platform module / crypto coprocessor?

I can think of a few reasons:

There wasn't any such features for x86 when the patch was created, other than AES-NI.

Many hardware platforms that have TPM, have it connected via a low-bandwidth LPC bus which would have nowhere near enough bandwidth for demand decryption/encryption of memory pages.

Hardware vendors can apparently turn these security features off as they wish, even if the hardware supports and was shipped with it :)

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#73
post #68

I don't know how this works but does this mean if someone gained physical access to your locked running computer, they could gain access to your full encrypted drive and anything saved on disk? My reasoning there is if you used an encrypted drive, the decryption key you type when booting up would be stored in memory for the duration of that boot. This seems alarming because it means if someone broke into your living…

Physical Access to a computer is almost always the fastest and easiest way to crack it down. Additionally, both Windows's BitLocker and Linux's dm-crypt are data at "rest" encryption. They are not responsible for the safety when your machine boots up. MAC and user password are the proper method when it's running.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#74
post #68

I don't know how this works but does this mean if someone gained physical access to your locked running computer, they could gain access to your full encrypted drive and anything saved on disk? My reasoning there is if you used an encrypted drive, the decryption key you type when booting up would be stored in memory for the duration of that boot. This seems alarming because it means if someone broke into your living…

If they have liquid nitrogen and a memory dumping boot disk, or a memory bus interceptor.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#75
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

This doesn't matter; it's post-sale enshittification... They didn't even wait to make the next model shittier!

Also, it probably wasn't the selling point, but it was the baseline of quality, and probably documented online or in manuals.

Furthermore, accepting this as normal opens the door to further post-sale enshittification of ALL things. Next thing you know, upgrades here and there are going to degrade the quality of products and services just because it wasn't explicitly written (think post-upgrade slowdowns of mobile phones to pressure people to buy newer ones).

This is THE slipperiest slope; and it's just taking place because the deregulation mafia is turning a blind eye to these tech cartels.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#78
post #62

It's pretty crazy that we have this entire segment of features that companies artificially restrict from the average person and overinflate the price of, for no real reason. GPU virtualization is another example of such a feature. The market segmentation arguments don't really work either, enterprises are paying the big bucks for more than just these standalone features.

Reminds me of subscription heated seats in bmw cars. The hardware is already there, you paid for it and you can’t use it unless you give the automaker a revenue stream on top of the tens of thousands you already paid for the car.

Same with some old IBM hardware: two CPUs were installed in each box, but if you bought only 1 CPU server other one is disabled via firmware.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#79
post #58
post #52

Earlier quoted context omitted.

If you ever had to use an iPhone that would just shut off randomly with like 30% battery "remaining", you'd probably be singing a different tune and appreciative your device became somewhat more usable with the changes.

I'd expect the battery charge estimation to be recalibrated to account for the reduced capacity, not the hardware being deliberately hobbled to hide it.

But it’s not a matter of total charge, but output, hence it shutting down even though there’s plenty of stored energy in the battery.
Post reply on HN