Live data from Hacker News

AMD silently removes memory encryption from consumer Ryzen CPUs

tomshardware.com

101–110 of 225 posts

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#101
post #31
post #19

Earlier quoted context omitted.

how do you know what threats I face? how do you know what threats journalists and whistleblowers face? this is approximately the same discussion as with ECC RAM: the benefits vastly outweigh the slight performance loss and die area increases.

ECC passively benefits everyone, even people who don't know what it is or why it's useful. Anyone can be a victim of random bit flips, it's not a targeted threat. Memory encryption, on the other hand, provides absolutely no benefit to 99.999% of users. If you consider yourself to be such a high value target that you suspect someone might gain physical access to your hardware without your knowledge and carry out extre…

Memory encryption can help mitigate much lower level attacks such as row hammer, these attacks get patched even average consumer devices.

No benefit for 99%? people said the same about FDE. Just as there is not a good enough excuse to not validate integrity and availability of data, it is not for confidentiality when its very much technically possible to do so.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#102

Earlier quoted context omitted.

Reminds me of that Seinfeld episode where George tries to move a Frogger arcade machine without powering it off in order to not lose his high score leaderboard. https://youtu.be/5etwHVarNgI?t=256

From a few years ago: > Five guys moving a server to a new datacenter without shutting it down. Without cutting it off from the internet. And as using a car would have been too easy, they used public transport. * https://www.youtube.com/watch?v=vQ5MA685ApE (DE audio, EN subs) See also perhaps: > The HotPlug allows hot seizure and removal of computers from the field to anywhere else. The HotPlug's patented technology…

Thats rough.

If anything, thats an indication to me to make a HA setup so you can power down 1 member.

Im not going to watch a video, honestly, but HA with a front-facing Zookeeper and sharded Postgres isnt super hard. Can be if you didnt initially plan for it.

Ideally, you need an odd amount of quorum machines to properly handle split brain decisions... But if its a money issue, you can technically get by with just 2, and accepting a possibility of split brain.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#103
post #74
post #68

I don't know how this works but does this mean if someone gained physical access to your locked running computer, they could gain access to your full encrypted drive and anything saved on disk? My reasoning there is if you used an encrypted drive, the decryption key you type when booting up would be stored in memory for the duration of that boot. This seems alarming because it means if someone broke into your living…

If they have liquid nitrogen and a memory dumping boot disk, or a memory bus interceptor.

Is this still a viable attack in 2026?

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#104
post #103
post #74

Earlier quoted context omitted.

If they have liquid nitrogen and a memory dumping boot disk, or a memory bus interceptor.

Is this still a viable attack in 2026?

if you have liquid nitrogen and a memory dumping boot disk, or a memory bus interceptor

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#106
post #91

Makes sense. The ECC in consumer line is what created an entire market for use in inexpensive web hosting. Then AMD created their EPYC variants, and it wasn’t clear what the difference was between the consumer & Epyc models.

No clear difference beyond the scaling to 6x the memory channels, 24x the memory capacity, 12x the core count, 6x the PCIe lanes, and ability to double (or nearly double) these with a 2nd socket. There are also a few features, like per VM memory encryption, which have only ever been on Epyc (and "real" Epyc, not just any Epyc branded consumer platforms).

Like the article hits spot on right at the start, it has nothing to do with needing to differentiate Epyc somehow and everything to with differentiating the PRO versions of the consumer CPUs:

> was suddenly no longer available on AMD CPUs outside the company's Pro lineup

The PRO variants are just the standard consumer CPU sold at a $ premium for enterprise targets. They have remote management firmware enabled, get longer firmware and support lifecycles, FIPS certification, and, now, memory encryption over the consumer branded version of the same CPU.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#107

Earlier quoted context omitted.

This doesn't matter; it's post-sale enshittification... They didn't even wait to make the next model shittier! Also, it probably wasn't the selling point, but it was the baseline of quality, and probably documented online or in manuals. Furthermore, accepting this as normal opens the door to further post-sale enshittification of ALL things. Next thing you know, upgrades here and there are going to degrade the quality…

This is FUD. We have no idea the reason why. Given it was never marketed, it's possible perhaps despite the feature being exposed it never worked correctly and AMD saw fit to just disable it rather than people get a false sense of security through it.

Why call out FUD when you only have more/different uncertainty to offer?

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#108
post #85

Earlier quoted context omitted.

Unless you live in North Korea, China, Russia, UK, France, Australia or Ireland it’s still illegal to coerce or force someone to give up their personal keys or passwords, so this feature is still useful against some law-bound adversaries in free countries.

Well, I live in Ireland but not sure what you refer to. Something being illegal does not imply it doesn't happen though.

law in question: https://www.irishstatutebook.ie/eli/2017/act/11/section/7/en...

and recent Supreme Court decision that upheld its constitutionality:

https://www.algoodbody.com/insights-publications/password-pr...

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#109

Hint: NSA said no.

Why did the NSA wait 9 years to say no & why does that explain the coincidence of the feature being supported in the PRO variants of the same CPU, which just happen to cost more?

If the NSA wanted to say no they'd just ask for some kind of back door and call it a day.

Post reply on HN