Live data from Hacker News

AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

tomshardware.com

41–45 of 45 posts

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#41

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

The 180 is incredible to see though. I remember when enforcing FDE was all the rage bc well, shit gets stolen. This stuff was a critical concern then. Apple got raked over the coals for months because they did nothing to prevent shoulder surfing (as if a phone could).

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#42

We paid for your things, AMD. If you want to strip some features from things we bought after the purchasing, you must ask me and every other customers for consents explicitly, with a reasonable explanation, and before the strip happens. If one of us show no consent, you cannot do that. ------------- See the github issue [1]. @benkilpatrick found out the problem in April. There was absolutely no consent asking informa…

Thanks for the Github links, it is interesting that AMD said they'll re-instate this for Ryzen 9000 series chips, but users are reporting it being disabled on 7000 (and maybe even AM4).

"It's been disabled on my 7700X with AGESA 1.3.0.1 on an ASUS TUF B650M PLUS WIFI"

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#43

Earlier quoted context omitted.

I think it's more a reference to Spectre and Meltdown and Rowhammer and a bazillion other hold-my-beer attacks that have never, ever been used in the wild but that everyone pays the price for by having their CPUs slowed down by the countermeasures. Applying Unicorn Repellant is fine when there's no cost, but it definitely has a cost in these cases.

How can you be so sure they have never been used in the wild? Surely not all uses of them get reported...

The same way I'm fairly sure that no-one's ever been attacked by a unicorn. There could be lots of unreported attacks, but I'm pretty sure there aren't any actual ones.

What we do have is millions of actual, real-world attacks (see any security body's top-ten list) that we aren't mitigating because we're too busy focusing on silly attacks that no-one ever uses.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#44

> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.

It converts some of silent bitflip errors into loud crashes, which is desirable in some use cases.

Re: AMD will reinstate memory encryption on Ryzen 9000 CPUs via BIOS update in July

#45
post #32

Earlier quoted context omitted.

So my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.

Does it run slower? I'd expect dedicated hardware to do that encryption/decryption, in which case there should be no difference.

I had read there was a ~5% slowdown with it enabled.
Post reply on HN