It's a shame there is no software-based memory encryption included in the linux kernel. Especially cloud providers can easily snoop all your keys and you have zero recourse.
AMD silently removes memory encryption from consumer Ryzen CPUs
111–120 of 225 posts
Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#112If you're this serious about security, you should be manufacturing your own hardware.
If you're serious about privsec you should use GrapheneOS.
Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#113Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#114Silent enshittification in the name of updates is getting out of hand. There are several evidences that downgrading BIOS/AGESA to below 1.2.7.0 to 1.2.0.3 brought back TSME for their AMD cpus.
I downgrade my bios as a price for my blind trust on AMD, and yes TSME is back.
You lost my trust AMD. The lesson learned is that if your PC with AMD cpu is stable, don't do any bios upgrade, as AGESA in the bios is adversarial to you, the users of AMD cpu.
Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#115Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#116Earlier quoted context omitted.
You shouldn't be remotely disabling hardware features in my opinion at all. It's not really like changing an API or something, this is like an update removing something from your car or another appliance years after you bought it.
Yeah, basically you'd trade uncertainty for the ability to remotely enable/disable hardware features not ready at launch I understand, which totally makes sense as a position, I probably agree with you. I think from AMD's side they like the option of being able to remotely enable things though, so new software updates in the future could be major releases enabling functionality that wasn't quite ready at launch. But,…
Even if you have the ability to remotely enable new features:
1. You shouldn’t use the same ability to disable existing features.
2. You shouldn’t enable them, either! It should be opt-in. Any kind of change has the potential to break something. Just don’t be changing my hardware without me initiating the change.
Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#117Earlier quoted context omitted.
This is FUD. We have no idea the reason why. Given it was never marketed, it's possible perhaps despite the feature being exposed it never worked correctly and AMD saw fit to just disable it rather than people get a false sense of security through it.
Why call out FUD when you only have more/different uncertainty to offer?
Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#118It's pretty crazy that we have this entire segment of features that companies artificially restrict from the average person and overinflate the price of, for no real reason. GPU virtualization is another example of such a feature. The market segmentation arguments don't really work either, enterprises are paying the big bucks for more than just these standalone features.
Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#119If you're this serious about security, you should be manufacturing your own hardware.
But even then? can you really trust the research and information about how to produce those ICs if you have not conducted that research yourself personally?
Re: AMD silently removes memory encryption from consumer Ryzen CPUs
#120Earlier quoted context omitted.
This doesn't matter; it's post-sale enshittification... They didn't even wait to make the next model shittier! Also, it probably wasn't the selling point, but it was the baseline of quality, and probably documented online or in manuals. Furthermore, accepting this as normal opens the door to further post-sale enshittification of ALL things. Next thing you know, upgrades here and there are going to degrade the quality…
This is FUD. We have no idea the reason why. Given it was never marketed, it's possible perhaps despite the feature being exposed it never worked correctly and AMD saw fit to just disable it rather than people get a false sense of security through it.
"no one uses it and there is a bug" may invite more questions or panic, but "that's all we're going to say" implies that Mythos found something scary, or that the NSA demanded they all get turned off.