Live data from Hacker News

AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

tomshardware.com

31–40 of 45 posts

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#31

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

If the bad guys have physical access to my consumer desktop, I'm already well and truly fucked.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#32

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

Does it run slower? I'd expect dedicated hardware to do that encryption/decryption, in which case there should be no difference.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#33

They’ve been doing a bunch of stuff in agesa updates regarding memory stability lately, and also recently broke and fixed setting manual speed on DDR5 memory with ECC enabled (basically any setting higher or lower than 5200mhz or something was ignored). I wonder if this was also something they just accidentally broke, or if it was an incompetent attempt at larger segmentation.

> and also recently broke and fixed setting manual speed on DDR5 memory with ECC enabled (basically any setting higher or lower than 5200mhz or something was ignored).

Do you know when this was fixed? I recently updated my B650D4U and ended up stuck at 5200MHz instead of 5600MHz. Asrock Rack don't seem to take every update, but I have had luck getting beta releases in the past when I've asked about specific versions.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#34
We paid for your things, AMD.

If you want to strip some features from things we bought after the purchasing, you must ask me and every other customers for consents explicitly, with a reasonable explanation, and before the strip happens. If one of us show no consent, you cannot do that.

-------------

See the github issue [1]. @benkilpatrick found out the problem in April. There was absolutely no consent asking information transparency at all. There was inefficient to no information even for people willing to spend THEIR OWN TIME to solve the problem. After about two months of back and forth with motherboard manufacturer, @benkilpatrick found out the problem stems from some components inside the bios, and the components came from AMD. Another ~three weeks passed and no problem resolution at all. It was after things blow up AMD PR came out and said something about "valuable feedback".

Wait, what if there's no enough pushback? What if this github issue as well as the problem it raised is ignored by all? Just see this thread, that thread [2] and whatnot. Is your customers going to screw themselves and being stripped silently for being your customers and believing that new bios will solve their problems without causing shenanigans?

-------------

I won't upgrade bios without future third-party bios integrity checks showing the problem is solved properly.

[1] https://github.com/AMDESE/AMDSEV/issues/292

[2] https://news.ycombinator.com/item?id=48582320

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#35
post #19

Earlier quoted context omitted.

You'd need physical access while it is running as the target is using it.

When the threat model is physical security, henchmen are also a consideration.

Yeah if you’re worried about someone getting physical access to your PC for information you should probably be more worried about someone beating that information out of you first.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#36

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

> as it protects against attacks where the attacker needs physical access to the device.

Doesn't it also protect against rowhammer-like attacks?

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#37

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

If it's not your top concern, you're probably a government employee with full security clearance and the "consumer desktop" doubles as a pirated game rig, top secret NAS and Twitter battle box.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#38
post #33

They’ve been doing a bunch of stuff in agesa updates regarding memory stability lately, and also recently broke and fixed setting manual speed on DDR5 memory with ECC enabled (basically any setting higher or lower than 5200mhz or something was ignored). I wonder if this was also something they just accidentally broke, or if it was an incompetent attempt at larger segmentation.

> and also recently broke and fixed setting manual speed on DDR5 memory with ECC enabled (basically any setting higher or lower than 5200mhz or something was ignored). Do you know when this was fixed? I recently updated my B650D4U and ended up stuck at 5200MHz instead of 5600MHz. Asrock Rack don't seem to take every update, but I have had luck getting beta releases in the past when I've asked about specific versions.

For Asrock, it should be fixed in any bios with 1.3.0.1b

Looking at Asrock consumer motherboards, it’s been rolled out to some but not all yet. The AGESA for that Asrock rack board looks way behind, so I’d definitely make a request to them to update since the squeaky wheel gets the grease if it’s going to at all.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#39
post #32

Earlier quoted context omitted.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

Does it run slower? I'd expect dedicated hardware to do that encryption/decryption, in which case there should be no difference.

I think it's more a reference to Spectre and Meltdown and Rowhammer and a bazillion other hold-my-beer attacks that have never, ever been used in the wild but that everyone pays the price for by having their CPUs slowed down by the countermeasures. Applying Unicorn Repellant is fine when there's no cost, but it definitely has a cost in these cases.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#40
post #32

Earlier quoted context omitted.

Does it run slower? I'd expect dedicated hardware to do that encryption/decryption, in which case there should be no difference.

I think it's more a reference to Spectre and Meltdown and Rowhammer and a bazillion other hold-my-beer attacks that have never, ever been used in the wild but that everyone pays the price for by having their CPUs slowed down by the countermeasures. Applying Unicorn Repellant is fine when there's no cost, but it definitely has a cost in these cases.

How can you be so sure they have never been used in the wild? Surely not all uses of them get reported...
Post reply on HN