Live data from Hacker News

Lenovo vendor locking Ryzen CPUs with AMD PSB

servethehome.com

181–190 of 234 posts

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#181
post #125

lenovo again.. when it's not shipping with rootkits (they did it twice!) and bloatware, it's about limiting HW a company to boycott

Is there any laptop manufacturer that doesn't ship complete bloat/mal/spy/ware in their products?

That is actually a good question. I am slowly starting to prepare to purchase a laptop for my wife. Lenovo is basically out based on principle here, but can I realistically convince her to use System76, which seems less bloat-oriented? I honestly don't know. It is not like she needs a powerful machine, but I simply do not want to support a customer-hostile company.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#182

Earlier quoted context omitted.

FWIW, they're not locked to Lenovo boards you just need to have a board that can be configured to not care about the PSB.

This is not correct. The locks does happen on the CPU level. If the board cannot provide a BIOS with a valid signature from the key that was burned into the CPU, the CPU will refuse to boot (PSB prevents it from booting)

Ah, you're right, I was reading the suggestions section of TFA as a the system works like this not that it would be nice if it worked liked this. My bad!

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#183
post #136

Earlier quoted context omitted.

Bad news is that US doesn't want to have anything with them.

At this point, their government has completely undermined foreign confidence in their semiconductor industry. I would be careful to avoid any processors from there, because the chance that it contains a backdoor is just too great to risk. Even if that is only a perceived risk and not a real one. American propaganda in recent years clearly set out to reach this new status quo, and it’s probably all smoke and little to…

No post body was provided.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#184

Earlier quoted context omitted.

It's been around a decade since Secure Boot first appeared and I remember well the opposition that had, along with a rallying cry based on the infamous Franklin quote. Unfortunately many of the opposition either accepted it or even defected, but the more this "security" stuff appears, the more I like that quote. It's succinct and gets the sentiment across very well.

Secure Boot is really quite separate from AMD PSB and actually does provide protection against certain attacks, no need for the double quotes. It's fortunate, not unfortunate, that we've gone past such irrational opposition to a reasonable extent. Irrational opposition like that makes it much harder to talk about what's actually important, such as PSB/PSP, without getting lumped together with the tinfoil crowd.

It's most definitely not "irrational opposition". It's the observation that computing systems have slowly become increasingly user-hostile in the name of "security", and the associated rise of authoritarianism.

There's no doubt it "does provide protection against certain attacks", but the thing is WE DON'T CARE. We don't want our freedoms slowly being eroded, we see the edges slowly creeping in, and the best way to do that is to take a strong DO NOT WANT attitude towards any such dubious steps in that direction.

Most people thought Stallman was in "the tinfoil crowd" 20 years ago. Yet his predictions have turned out more correct than not.

Slowly, the frog boils...

https://news.ycombinator.com/item?id=29859106

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#186
post #70
post #5

All in the name of "security" of course.

All this security is making me feel claustrophobic.

No kidding. They're squeezing us slowly.

There's a saying about how the best way to make people unware of what freedoms they're losing is to ensure they never had freedom in the first place.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#187
post #151

Earlier quoted context omitted.

Seems like you are not aware of Intel ME past vulnerabilities.

That would imply that basically every single piece of software ever made is malware.

Not sure about every single piece of software, but what do you call closed source relatively hidden software in hardware that grants you full access with empty password, running on unaccountable number of computers for many years ?

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#188
post #168

Earlier quoted context omitted.

A computer that requires the firmware to be replaced to boot Linux is already at the point where 99% of users are just not going to install Linux (I've personally ported Coreboot to two of my laptops, and even I would never buy hardware that required me to do that before I could run Linux). And, well, you may well have never heard of attacks that would be mitigated by these technologies, but I have. Firmware-based at…

> And, well, you may well have never heard of attacks that would be mitigated by these technologies, but I have. Firmware-based attacks have existed for over a decade This is a pure cash grab by Lenovo and AMD, not about mitigating attacks. If this were about platform security for the benefit of the owner, it would not be permanent, nor enabled by default. All this does is create more e-waste and nuke resale value fo…

> it would not be permanent

If it's not permanent then it doesn't work - any plausible mechanism for allowing it to be disabled can be triggered by whoever's replacing your firmware (which makes AMD's approach somewhat bewildering here, given that you can just replace the CPU). But yes, I agree that enabling it by default is probably the wrong approach here.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#189
post #151

Earlier quoted context omitted.

>malware like the Intel managament engine The code is not malicious please do not call it malware. Your computer already has dozens of other chips running proprietary software on them. It's just a normal part of PC components except since a CPU doesn't have a board the chip is built right in.

Seems like you are not aware of Intel ME past vulnerabilities.

The only major one required an attacker to open your machine and attach a flasher.

Usually it's considered game over if an attacker has physical access to your machine.

Re: Lenovo vendor locking Ryzen CPUs with AMD PSB

#190

The problem is the AMD PSB functionality in itself. It should be considered malware like the Intel managament engine and thus refused by users. It's a second processor that runs a proprietary firmware signed by the vendor (that the user cannot modify or substitute entirely with a FLOSS alternative) that vendors can use do harm to the user. The AMD PSB can also be used to lock down a processor to enforce secure boot a…

I find it funny, how software, bugs, and possibly malicious intents are considered way differently than the same thing in practically any other industry.

You buy a Toyota, they screw up the floormats, causing a potentially dangerous situation, millions of cars recalled, issue fixed. Volkswagen knows about an intentional 'screwup' (the exhaust cheating), they get caught, class actions, people return cars, get monetary compensation, etc.

You buy an Intel, after Intel knows about a screwup... whoops... here's a software fix that cripples your cpus performance. Whoops, didnt fix everything, disable hyperthreading. Money back? Nope. Any other kind of compensation? Nope.

Same with software.. they put an EULA there, and they're somehow not responsible for anything anymore.

Here, you might lose a functionality that made you buy that computer in the first place, and "whoops".

Post reply on HN