Live data from Hacker News

AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

tomshardware.com

21–30 of 45 posts

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#21
post #19

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

You'd need physical access while it is running as the target is using it.

When the threat model is physical security, henchmen are also a consideration.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#22

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#23

They’ve been doing a bunch of stuff in agesa updates regarding memory stability lately, and also recently broke and fixed setting manual speed on DDR5 memory with ECC enabled (basically any setting higher or lower than 5200mhz or something was ignored). I wonder if this was also something they just accidentally broke, or if it was an incompetent attempt at larger segmentation.

We're talking about a company that five generations into its processor family still hasn't been able to figure out how to have USB work properly and reliably.

AMD Adrenalin, their software that manages things video/GPU features like clip saving, performance settings, game optimizations, update monitoring, performance overlaying, etc - is so fucking bad that if your mouse is set to a refresh rate over 500hz, it is virtually unusable because the mouse cursor takes half a second to respond to inputs. This is running on a card one step down from the flagship, current generation.

Don't even get me started about ROCm on Windows.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#24
post #20
post #16

Earlier quoted context omitted.

Physical hardware products shouldn't lose features after launch. If this was a "mistaken" feature which they suggested it was they should have disabled it on future chips.

A lot of this has to do with segmenting the market into high-end and low-end products. When they were the underdog to Intel, they gave away lots of premium features to beat Intel. Since they got more popular, AMD has been taking away features, or not upgrading old tech, from their desktop/gaming CPUs: Their DDR5 interface is gimped, being slower than Intel now, and still limited to dual channel. Their chipset link is…

None of that is a good rationale for patching the firmware to retroactively remove things from devices that were sold years ago. It's an abuse of a mechanism that's ostensibly meant for security fixes and maybe perf improvements, which is a dangerous game because it incentivizes people to just not update the firmware at all, which is a worse scenario for both parties than just resolving to not include the feature in CPUs going forward if it's such a huge loss to include it.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#25
post #8

I'm a little puzzled by the uproar given that all the oneline chatter seems to suggest nobody is using this. If this was AVX512 or something I could understand the give it back reaction...

I think it's more the principle. CPU firmware upgrades are not supposed be used for things like this, and if it became normal to use them for removing features, it would just lead to people not updating the firmware at all, and that's not a good scenario for anyone.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#27

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

[deleted]

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#29

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

So you turn it off by default in BIOS and allow those that feel it's useful to them to enable it, and you solve for both sides of the problem.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#30

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

The last few companies have all had desktops in datacenters with the local PC just a virtual terminal.
Post reply on HN