Live data from Hacker News

AMD silently removes memory encryption from consumer Ryzen CPUs

tomshardware.com

121–130 of 225 posts

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#121
post #72

Earlier quoted context omitted.

> You have to store the encryption key in CPU registers and ensure it's not saved to RAM during task switching or power suspend operations. Interesting insight. Any reason why the key can't be kept exclusively in the secure enclave / trusted platform module / crypto coprocessor?

I can think of a few reasons: There wasn't any such features for x86 when the patch was created, other than AES-NI. Many hardware platforms that have TPM, have it connected via a low-bandwidth LPC bus which would have nowhere near enough bandwidth for demand decryption/encryption of memory pages. Hardware vendors can apparently turn these security features off as they wish, even if the hardware supports and was shipp…

> Many hardware platforms that have TPM, have it connected via a low-bandwidth LPC bus which would have nowhere near enough bandwidth for demand decryption/encryption of memory pages.

Ah, of course. I was more thinking along the lines of "CPU loads the key for decrypting RAM directly from the TMP into registers, and reloads it from there after waking from suspend or after a task switch has refilled those registers".

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#123
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

There's plenty of features in products I buy which aren't "marketed", which I nonetheless get upset if are suddenly removed.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#124
post #62

It's pretty crazy that we have this entire segment of features that companies artificially restrict from the average person and overinflate the price of, for no real reason. GPU virtualization is another example of such a feature. The market segmentation arguments don't really work either, enterprises are paying the big bucks for more than just these standalone features.

I think intel tried to offer GPU virtualisation with their consumer offerings but not sure what happened to that.

Yes, I think Intel did offer that, but I recall hearing their software wasn't very good.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#125
post #91

Makes sense. The ECC in consumer line is what created an entire market for use in inexpensive web hosting. Then AMD created their EPYC variants, and it wasn’t clear what the difference was between the consumer & Epyc models.

No clear difference beyond the scaling to 6x the memory channels, 24x the memory capacity, 12x the core count, 6x the PCIe lanes, and ability to double (or nearly double) these with a 2nd socket. There are also a few features, like per VM memory encryption, which have only ever been on Epyc (and "real" Epyc, not just any Epyc branded consumer platforms). Like the article hits spot on right at the start, it has nothin…

What’s the different between these two:

Consumer:

https://www.amd.com/en/products/processors/desktops/ryzen/90...

EPYC variant:

https://www.amd.com/en/products/processors/server/epyc/4005-...

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#126

Earlier quoted context omitted.

Yeah, basically you'd trade uncertainty for the ability to remotely enable/disable hardware features not ready at launch I understand, which totally makes sense as a position, I probably agree with you. I think from AMD's side they like the option of being able to remotely enable things though, so new software updates in the future could be major releases enabling functionality that wasn't quite ready at launch. But,…

How hypothetical is this situation? Even if you have the ability to remotely enable new features: 1. You shouldn’t use the same ability to disable existing features. 2. You shouldn’t enable them, either! It should be opt-in. Any kind of change has the potential to break something. Just don’t be changing my hardware without me initiating the change.

Overall I agree with you, and aim for the same, as a professional user I can't really have my environment and hardware change automatically, I really despise that too!

> Just don’t be changing my hardware without me initiating the change

In this case it seems to have been disabled in future firmware, so "you" did initiate the change, as you did an firmware upgrade that included the change. Still, shitty to sneak it in, I agree, but the feature wouldn't literally be there one day then not the next, requires human initiation at least.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#127
post #108

Earlier quoted context omitted.

Well, I live in Ireland but not sure what you refer to. Something being illegal does not imply it doesn't happen though.

law in question: https://www.irishstatutebook.ie/eli/2017/act/11/section/7/en... and recent Supreme Court decision that upheld its constitutionality: https://www.algoodbody.com/insights-publications/password-pr...

What are you trying to prove? He never said you're wrong, just the fact that something is illegal doesn't mean that it won't happen to you, just that it's illegal - those are just words written in a book somewhere. Even so-called law bound adversaries break the law all the time. A cop beating you senseless or breaking into your home is illegal, but it happens all the time. You're welcome to sue after the fact.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#128
post #123
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

There's plenty of features in products I buy which aren't "marketed", which I nonetheless get upset if are suddenly removed.

[flagged]

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#129

Earlier quoted context omitted.

Many many people use consumer CPUs for gaming servers.

So reading between the lines, you're saying it's bad for AMD to disable undocumented features because people still might have bought them for those undocumented features, particularly for gaming servers?

Yes.

> particularly for gaming servers

Not "particularly" but that's one example.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#130
post #108

Earlier quoted context omitted.

law in question: https://www.irishstatutebook.ie/eli/2017/act/11/section/7/en... and recent Supreme Court decision that upheld its constitutionality: https://www.algoodbody.com/insights-publications/password-pr...

What are you trying to prove? He never said you're wrong, just the fact that something is illegal doesn't mean that it won't happen to you, just that it's illegal - those are just words written in a book somewhere. Even so-called law bound adversaries break the law all the time. A cop beating you senseless or breaking into your home is illegal, but it happens all the time. You're welcome to sue after the fact.

This is not relevant to memory encryption, after all the police could just plant any false evidence. You use video camera/CCTV and other evidence gathering to document such illegal police action.

Suing after the fact is a valid strategy and in free countries this would allow you to exclude illegally obtained evidence or evidence lacking proper chain of custody.

Post reply on HN