Live data from Hacker News

AMD silently removes memory encryption from consumer Ryzen CPUs

tomshardware.com

151–160 of 225 posts

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#151
post #85

Earlier quoted context omitted.

Unless you live in North Korea, China, Russia, UK, France, Australia or Ireland it’s still illegal to coerce or force someone to give up their personal keys or passwords, so this feature is still useful against some law-bound adversaries in free countries.

The West just a few years ago declared that at airport entry points, no one is including their citizen is not protected by any law when it comes to providing access to your private stuff.

Don’t bring your sensitive data to airports.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#153
post #132

Earlier quoted context omitted.

A great example of a non-sequitur. I will interpret this to mean you concede and are not interested in continuing this conversation.

Why are you upset about the removal of this particular “feature”?

Let me put it this way.

My oven has a proofing feature. It wasn't really advertised, it's just there. I like that feature and I use that feature when baking.

If one day my oven manufacturer pushed an update which removed my proofing feature, I'd be upset.

The same could be said for encrypted memory. If you as a computer owner discovered and turned on encrypted memory because you wanted to feel a bit more secure about your hardware getting stolen. You'd probably be upset that on a normal firmware update that feature suddenly went away. Not because the hardware doesn't supported it or didn't support it. Not because AMD's firmware didn't or couldn't support it. But because someone in an AMD product management team said "Woopsie, that's an enterprise feature, we better disable that".

Completely different story if these CPUs never supported that feature. Completely different story if future CPUs didn't have that feature or had it disabled in firmware. Heck, even a different story if with the disable AMD also said "We disabled this because there's an unrecoverable fault in the memory controller which causes memory corruption."

I have to assume the reason wasn't because of a bug in the feature, but rather because management decided the feature wasn't supposed to be there.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#155
post #96

Earlier quoted context omitted.

it's exactly why we're not allowed a competitive market for CPUs we could all be burning our own tiny ~300nm feature size ICs at home for around the price of a blu ray burner and a dark room setup. Our silicon limitations are not for a lack of hardware, but rather a lack of freedom.

> a lack of freedom > ~300nm feature size Can you point to a specific regulation that prevents me from crafting shitty semiconductors in my shed? I am pretty sure there are entire YouTube channels dedicated to this.

IP laws. You personally might be able to do this. But should you attempt to sell a device that makes it easy for anyone to do, you will get sued into oblivion.

There's a big difference.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#156
post #28
post #22

It's a shame there is no software-based memory encryption included in the linux kernel. Especially cloud providers can easily snoop all your keys and you have zero recourse.

There was a patch called Tresor that did this, but I don't think it was updated for a long time. You have to store the encryption key in CPU registers and ensure it's not saved to RAM during task switching or power suspend operations. Tresor used x86-specific debug registers for it, but you could potentially use unused SIMD registers if you masked-off the CPUID bits for them and disabled them for access by user-space…

Realistically as an Europeans we have the security threat of backdoored components from Epstein's colleagues at five eyes which are used for mass-surveillance of VMs at European hosters such as Hetzner. And every time you add a configuration option like memory encryption it makes their drive-by mass surveillance a tiny bit more difficult and hopefully easier to detect for the sysadmins at Hetzner.

IMO using the specialized CPU instructions (AES) is not clever because they'd obviously have backdoored that instruction to simply remember all keys that were used.

It's part of a defense-in-depth approach that Europe unfortunately needs as Europeans are considered as foreigners without any human rights by the five eyes community. America and their major tech leaders have made that abundantly clear to Europe, including the hitler salute as cherry on top.

I'm quite sad we have reached this situation, but if one is serious about security these things need to be discussed and if possible implemented.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#157
post #103
post #74

Earlier quoted context omitted.

If they have liquid nitrogen and a memory dumping boot disk, or a memory bus interceptor.

Is this still a viable attack in 2026?

Yes. Also depending on the implementation (ie if it's not an outdated Intel machine) it is presumably also vulnerable to snooping the memory bus while it's running. Note that this active attack applies regardless of encryption and impacts even enterprise SKUs. https://tee.fail/

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#158
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

So that burn notice episode about freezing ram is real? Damn, thought they made it up

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#159
post #12

This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.

So that burn notice episode about freezing ram is real? Damn, thought they made it up

I remember reading a study on that topic >15 years ago

https://en.wikipedia.org/wiki/Cold_boot_attack

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#160

Earlier quoted context omitted.

What’s the different between these two: Consumer: https://www.amd.com/en/products/processors/desktops/ryzen/90... EPYC variant: https://www.amd.com/en/products/processors/server/epyc/4005-...

The Epyc 4585PX falls into the `(and "real" Epyc, not just any Epyc branded consumer platforms)` note. I.e. it is the same CPU as the AMD Ryzen 9 PRO 9965X3D, branded differently because it is certified against "server" branded motherboards instead of "standard" PC motherboards (same socket/chipset though, outside firmware validation the two are swappable). It carries none of the actual Epyc feature sets, just the PR…

Hence why I said in my original post:

>>Makes sense. The ECC in consumer line is what created an entire market for use in inexpensive web hosting. Then AMD created their EPYC variants, and it wasn’t clear what the difference was between the consumer & Epyc models. reply

Post reply on HN