Live data from Hacker News

AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

tomshardware.com

11–20 of 45 posts

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#11
post #8

I'm a little puzzled by the uproar given that all the oneline chatter seems to suggest nobody is using this. If this was AVX512 or something I could understand the give it back reaction...

Judging by the Reddit threads I saw, A LOT of people were upset even though it was clear that they had not idea what the feature actually provided beyond “encryption”. I’d guess that the majority assumed that the change would result in them basically having to “encryption” in affected AMD devices any more in some vague general sense.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#13
post #8

I'm a little puzzled by the uproar given that all the oneline chatter seems to suggest nobody is using this. If this was AVX512 or something I could understand the give it back reaction...

Judging by the Reddit threads I saw, A LOT of people were upset even though it was clear that they had not idea what the feature actually provided beyond “encryption”. I’d guess that the majority assumed that the change would result in them basically having to “encryption” in affected AMD devices any more in some vague general sense.

Exactly. Thus far I've seen 1 person use it...and they seemed to believe it provides rowhammer benefit...so somewhat tangential

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#14
post #7

Thought there were cases where other devices could have direct access to RAM (e.g. DMA, PCIe controllers outside the CPU, etc.). Wonder how that works in conjunction.

There are many ways it can work depending on the cpu:

1. No dma, instead you use bounce buffers and the cpu manually encrypts and decrypts on behalf of the pcie

2. The IOMMU sets certain pages as unencrypted and ensures the pcie only accesses those pages and that part of ram alone is now not encrypted.

3. Newer pcie devices use the TDISP(handshake) and IDE(aes gcm hardware module related stuff) protocols to do encrypted communication with the CPUs PCIe root hub, where this functionality is called TIO i.e trusted io on amd and TX connect on intel. As far as nvidia GPUs go which is where I have used this, H100 onwards have the feature. Only server xeons and turins etc support this feature on the cpu side. I think some server SSDs do too. Here you get full encryption full DMA at full bandwidth.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#15
post #4

People don’t like things being taken away, even if I don’t think many people are actually using this feature. I don’t even think its exposed in most BIOS’s

And it does reduce memory speed by about 0.5-1%.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#16
post #8

I'm a little puzzled by the uproar given that all the oneline chatter seems to suggest nobody is using this. If this was AVX512 or something I could understand the give it back reaction...

Physical hardware products shouldn't lose features after launch. If this was a "mistaken" feature which they suggested it was they should have disabled it on future chips.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#17
> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device.

If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#19

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

You'd need physical access while it is running as the target is using it.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#20
post #16
post #8

I'm a little puzzled by the uproar given that all the oneline chatter seems to suggest nobody is using this. If this was AVX512 or something I could understand the give it back reaction...

Physical hardware products shouldn't lose features after launch. If this was a "mistaken" feature which they suggested it was they should have disabled it on future chips.

A lot of this has to do with segmenting the market into high-end and low-end products.

When they were the underdog to Intel, they gave away lots of premium features to beat Intel.

Since they got more popular, AMD has been taking away features, or not upgrading old tech, from their desktop/gaming CPUs: Their DDR5 interface is gimped, being slower than Intel now, and still limited to dual channel. Their chipset link is still PCIe 4x4 the same as two generations ago.

If you want these features now, you need a server product.

Post reply on HN