Live data from Hacker News

AMD silently removes memory encryption from consumer Ryzen CPUs

tomshardware.com

61–70 of 225 posts

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#62
It's pretty crazy that we have this entire segment of features that companies artificially restrict from the average person and overinflate the price of, for no real reason. GPU virtualization is another example of such a feature.

The market segmentation arguments don't really work either, enterprises are paying the big bucks for more than just these standalone features.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#63
post #38
post #27

I had this enabled as it protects against RAMbleed/ECC errors, so it's not limited to physical attacks.

Are you sure? I thought it's just AES without any authentication.

Which encrypts each cache line with a key unknown to the attacker. This means an attacker can't target individual bits. Every change affects at least one AES encrypted block. It's much stronger than any normal defence against row hammer in that regard because flipping a single bit in plaintext changes ~half the bits in the ciphertext. It's similar to how Apple uses always on disk encryption instead of the normal means to limit run length in their NAND flash controllers. If the encryption is "off" it just means the decryption key is stored somewhere in the trusted enclave.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#64
post #4

If it can be silently removed was it a security feature? Whilst I hate companies paying engineers to make things worse just to segment their market; I am not really seeing this as an important feature outside the data-center? If an evil-maid has hardware access they hack the USB and/or PCI not the RAM surely?

Removing it required AMD's firmware code signing keys. If an attacker has those and some time they can do much worse.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#65
post #5

Earlier quoted context omitted.

> To be fair to AMD, there is no clear indication that the company ever publicly advertised TSME as a consumer Ryzen feature. A feature that was possibly accidentally enabled on consumer chips is now being disabled. I would guess that the number of owners of consumer chips who also relied on them for encryption is exceedingly small. The primary concern persists. The manufacturer has an exceptional amount of control o…

> I would guess that the number of owners of consumer chips who also relied on them for encryption is exceedingly small. I guarantee you that there's one small company that put 1,000 of these chips in a server room or datacentre though, and they're now completely boned.

In that case I would expect them to try and work something out with AMD directly instead of building a company on undocumented features.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#66
post #62

It's pretty crazy that we have this entire segment of features that companies artificially restrict from the average person and overinflate the price of, for no real reason. GPU virtualization is another example of such a feature. The market segmentation arguments don't really work either, enterprises are paying the big bucks for more than just these standalone features.

Reminds me of subscription heated seats in bmw cars. The hardware is already there, you paid for it and you can’t use it unless you give the automaker a revenue stream on top of the tens of thousands you already paid for the car.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#68
I don't know how this works but does this mean if someone gained physical access to your locked running computer, they could gain access to your full encrypted drive and anything saved on disk?

My reasoning there is if you used an encrypted drive, the decryption key you type when booting up would be stored in memory for the duration of that boot.

This seems alarming because it means if someone broke into your living quarters they can bypass all forms of disk encryption if your machine was on and locked. Encrypting your disks seems like a reasonable thing to want to do with consumer grade hardware.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#69

This sort of shenanigan is why it’s important to have a competitive market for CPUs.

it's exactly why we're not allowed a competitive market for CPUs

we could all be burning our own tiny ~300nm feature size ICs at home for around the price of a blu ray burner and a dark room setup. Our silicon limitations are not for a lack of hardware, but rather a lack of freedom.

Re: AMD silently removes memory encryption from consumer Ryzen CPUs

#70
post #5

Earlier quoted context omitted.

> To be fair to AMD, there is no clear indication that the company ever publicly advertised TSME as a consumer Ryzen feature. A feature that was possibly accidentally enabled on consumer chips is now being disabled. I would guess that the number of owners of consumer chips who also relied on them for encryption is exceedingly small. The primary concern persists. The manufacturer has an exceptional amount of control o…

> I would guess that the number of owners of consumer chips who also relied on them for encryption is exceedingly small. I guarantee you that there's one small company that put 1,000 of these chips in a server room or datacentre though, and they're now completely boned.

Just dont upgrade the Mainboard firmware then
Post reply on HN