Lenovo vendor locking Ryzen CPUs with AMD PSB
servethehome.com
servethehome.com
The AMD PSB can also be used to lock down a processor to enforce secure boot and thus don't let you run an unsigned operating system, i.e. no longer allowing you to run Linux on your machine that comes out of the factory with Windows preinstalled. That would be a very very bad thing.
Unfortunately both for Intel and AMD you don't have choices these days. I'm hoping someone develops a processor based on the RISCV architecture (a free architecture that doesn't include that shit) to be used in a computer entirely under the control of the user (hardware and software) and not the corporation that makes it.
We live in a world where people talk about Thinkpads vs Macbook Pros, but for 99% of the world laptops are appliances they buy like we'd buy a toaster.
They don't care that they can't run Linux, if anything onerous code signing requirements ala mobile devices would be great for the safety of their devices with minimal effects on what they can do.
-
I'm not saying I want the market for power users to die, I'm one of them after all, but I also feel like these conversations on HN are often disconnected from the reality most people live in...
This isn't really a "they don't know better so they don't complain", this is a "even if they knew better they wouldn't complain"
The more fence sitters you convince that things are possible, pushes the fence further and further towards the other side.
There might be billions of people buying computers, but the set that has any opinion on boot code signing requirements is not large enough to cause any significant impact on the market as a whole.
There are companies that cater to these niche markets, like Pine/Framework/System76/Purism. They are tiny. Dell sells more computers in a single contract than all of these other companies have sold over their entire existence combined.
What impact might occur if a government like France were to require in the future only RISC V architectures with free boot loaders, of if the US government or a large corporation required use of measured boot to see at boot-time if the boot code or subsequent OS had been compromised?
With persistent threat actors and the falling price of processing power, I wouldn't be surprised if in the next ten years some larger organizations (or tens of thousands of small businesses) start demanding this kind if IT security from their vendors.
[0] (in French, of course) https://sill.etalab.gouv.fr/fr/software and their repo, https://github.com/disic/sill.
> The hypothetical homogeneous group 'they' you refer to doesn't exist
They do exist. Making wrong statements with conviction doesn't make it true.
You can look Chromebook sales figures, you can look at the best selling laptops at major retailers, you can look at what's driving record laptop sales, look at price points that are soaring, look at the mobile space...
-
> It's billions of people and 'they' feel many ways.
Which is why we draw conclusions based on a large sample size like I did above. You're never going to be able to consider billions of points of view, so yes, you need to try and find the common thread in their preferences and usages.
-
> By painting with a common brush, you shut down discussions of what could be and encourage fence sitters to give up.
No, by painting with a common brush, you can have actual useful discussions about the reality of things, rather than espousing your own personal whims.
-
> Let's talk about why it's possible, easy to do, and how to do it.
a) Where did my comment say it's impossible?
b) It's not easy to do or it wouldn't have existed in the first place. The whole point of my comment is saying that you need to figure out how to do it taking the current reality of things into context.
If the world thought how HN does we'd already have bills banning IME and PSB. So it doesn't. You can't pretend that people actually are a little nudge away from caring about this, or you'll quickly find that you're wrong and nothing will have actually changed.
-
> The more fence sitters you convince that things are possible, pushes the fence further and further towards the other side.
Again, what you could do if you believed that fence sitters were some large portion of laptop buyers is do what I've done, show some indications of this. Show us how niche efforts aimed at power users aren't the only rumblings about how awful locked down computing is.
What you're doing is still painting a group with a large brush, except you're not even showing us where you got the paint.
You get what I mean? So yeah, my recommendation is that we all talk like things are easy to make better, instead of saying, "too late its all over" because you'll encourage more people to try which I assume you agree is a good thing but if not, I guess to each their own.
Instead of trying to act like most people will ever care about locked bootloaders and PSB style co-processors, why don't we accept that they don't, they won't, and see what can happen from there?
An example of that is looking at it from a national security perspective. If you can paint it as a vulnerability to the tech industry you could see movement without the sisyphean task of convincing people that this stuff matters in their day-to-day lives
One would suppose instead that the logical thing to do is create financial opportunities that wouldn't otherwise exist by restricting what you can do without allowing them to insert themselves in the revenue stream.
I recall a long junked verizon phone I owned before android was a thing that could only ever be used with verizon. Despite paying for the phone in full including its GPS because Verizon had full control of the platform the only way to actually use the GPS was to pay Verizon $10 per month for navigation.
An environment where I could repurpose my existing phone instead of buying a new one when I switched carriers, where I could keep my phone number even, or one in which actually using the GPS didn't cost as much over time as the entire phone didn't exist but if you asked me at the time if I would like to live in our present universe or one which those restrictions remained the norm I should easily be able to answer.
Hacker news is about aggregating interesting things to read not a collection of grievances. For example this thread is about tech and if half of it was random grievances it would be a shitty website. Asking someone if they sympathize with your issue and asking them if you can paint it on the side of their house will get you two very different answers.
You and other tenants need to get together and either sue or more broadly look at how misdeeds by landlords are handled in your city and or state.
> You and other tenants need to get together and either sue or more broadly look at how misdeeds by landlords are handled in your city and or state.
We've had 3,200 people visit the site in the last 3 days. We're on our way.
This is why we need government intervention. If laws dictated that computing equipment etc. sold to the GP couldn't have 'locks' on them then these problems would instantly disappear.
Such laws can be easily be justified on grounds of (a) stopping monopolistic practices (anti-monopoly laws), and (b) minimizing e-waste.
This won't happen unless there's pressure on government like there has been over the right to repair from the Right to Repair movement. In fact such pressure could come from an extension of the group's current activities.
Well, that clearly didn’t happen with ME. Intel’s market share gradually grew for the decade after ME was introduced.
There is nothing stopping RISC-V SoC/CPU vendors from tacking it on.
With RISC-V, there is pretty much no such obligation. It's an open spec, there is no licensing fee and there isn't an obligation to add hardware susceptibilities. Chinese companies will (and are) manufacture chips like this at the lowest cost possible, likely eschewing any black-box m53s running Minix that you'd find on an American CPU. It also opens the possibility for more bespoke chip designs (as it's a modular ISA), and hopefully dividing the market between security-conscious products and consumer ones will stop all devices from being digitally wiretapped.
It's all speculation right now, but it's highly unlikely that RISC-V will be pozzed in the same way x86 or even modern ARM clusters are. There's too much competition, too much money to be made, and too few incentives. Suffice to say, you're probably going to hear the three-letter agencies complaining about "unsafe Chinese chips" soon or something equally stupid.
This is a false narrative, these management engines were added because large (corporate) customers of the major CPU vendors asked for them. Enterprise IT shops love stuff like this, anything to help them tame the unruly beast of asset inventory and management. This is the same reason things like iLO and DRAC exist, and they have all of the same types of bugs for the same core reason.
Not only does the government not want management engines, the ability to turn them off using HAP is courtesy of the US government (namely the NSA!) asking for a feature to disable it.
The main problem here is that the truth is boring, and the conspiracy theory sounds much more interesting.
https://www.csoonline.com/article/3220476/researchers-say-no...
There was a time when HP sold servers that could be up to say, 8 cores but only two were on by default and you cloud license the rest. It was cheaper to shop the hardware and software gate it rather than limit it and have a process in the middle.
Also, customer CPUs are often (due to binning) rebranded Enterprise CPUs that were rejected (or just not purchased) for whatever reason, or vice versa. Easier to build ME on them all and configure it later.
Your ECC memory? It's something Intel just flips on or off depending on how they want to sell the chip - many Core i7s and i9s have it on-die but you can't use it. That's because it might be useful on a Xeon Platinum equivalent.
Another reason is that ME (and PSP) are used to assert "security" of "Protected Media Path", which is part of streaming services DRM.
It's not the only way to do it, sure, but there's a reason why IBM POWER designs have approximately 2.1x amount of cores that is stated in the spec - pretty much every core has a smaller, simpler one dedicated to keeping the big one running without melting and helping transition to low-power states and back, and there are at least two more cores whose only job is handling some of the early loading of code from flash. Part of why they have those cores is that since POWER8 there was a shift towards more standalone operation without external controller chip (and POWER9 even describes such boot process in manual). For comparison, traditionally the FSP (aka BMC) on IBM POWER systems initialized all of hardware before the CPU would execute first instruction, puppeting the CPU buses through debug interface.
Sure you're open to buy RISC-V CPUs from China but how are you going to be certain that they have no backdoors?
From a purely technical standpoint, I agree (and wouldn't put it past Intel either). My argument is that having an open ISA makes it easier for manufacturers to compete with each other, which in turn makes it harder for interested parties to pin down every CPU manufacturer and punch holes in their individual designs.
> Sure you're open to buy RISC-V CPUs from China but how are you going to be certain that they have no backdoors?
Pragmatically, you can't. My point though was more that open ISAs give us options to buy hardware that doesn't get designed domestically, which is the main enabler for companies like AMD, Intel and Apple, and moreover, the government. If one chip is confirmed to be vulnerable in some way, you'll have legitimate competitors to choose from.
There seems to be a bit of a consistent thread running through lots of discussions that RISC-V because its 'open' magically solves all sorts of problems - it does have some advantages - but it doesn't solve these issues any more than Arm does (and Arm already has massive diversity of supply and billions of CPUs shipped without ME type issues).
Surely you can't think the architecture itself is the differentiator. x86 didn't have all of this security 20 years ago, give engineers a few years of time to throw some locks on a risc-v chip and it'll be Enterprise Ready™ in no time.
Anyone that wants to be 100% sure of the supply chain has to move away from globalization.
I still cannot understand why the US and other countries with high tech allowed themselves to become so absolutely dependent on China.
When their own companies killed of local manufacturing and went to China out of greed and increased profits then governments should have stepped in on strategic grounds, so why didn't they?
It was obvious to me some 25 years ago and I've no monopoly on this insight so they must have been well aware that this would happen. In essence, these countries have been shooting themselves in the feet for decades.
The question is why.
Edit: I can remember the time when the US military required certain components, chips etc. to be able to be second-sourced from multiple manufacturers before they were incorporated into equipment. Does anyone else remember this?
Clearly governments, not only the US, have been aware of the problem for many decades and have chosen to do nothing about it. Moreover, what brought them to abandon this once good policy in the first instance?
A CPU without the user-hostile features but still able to run the massive existing software base would be ideal.
On the other side RISCV instruction set is far simpler, being a RISC instruction set it decides to not have advanced optimizations in the processor (even better, none at all) and leave the optimization work to the compiler, that not only simplifies the processor, but also reduces the surface of attack of the processor (Meltown, Spectre, and all these attacks are just impossible on RISCV!). Of course that has a performance penalty, but since you simplify the processor you can just put more core in the saved space right?
What I'm referring to is the expiration of patents from the P6 era, which would mean all the uop-based stuff is now free to implement.
What a lot of the RISC hype doesn't understand is the huge value in backwards compatibility --- you can have your "100% free" world but it'll forever remain niche. We need to accommodate the proprietary world if we want any chance of freedom winning; and not try to divide the world of computing.
And they will stay at that level, is the parent's point, which is 25+ years before today and thus affordable to clone and fabricate. It's not about 486 or for that matter 8086 beinh difficult...
And who would make the tens of billions of investment to build a fab for that?
Otherwise with x86 is more complex: you can choose between Intel and AMD (that has bought the license for the x86 instruction set - not something cheap to get), and both of them had their backdoor processor inside the computer (at least on Intel there are ways to disable it, as far as I know with AMD is more difficult if not impossible to do).
Only the base RISC V is guaranteed thanks extensions.
Also you are forgetting that just like Android and ARM, there are other forces at play that don't make it as easy in practice as FOSS advocates wish for.
I remembered hearing that same line when I bought a Raspberry Pi in 2012. "It's useless! You can't run x86 software on it, so what's the point?"
Flash-forwards a decade and now Graviton instances are blowing up like nothing else in the industry. RISC-V is in a very similar position to ARM 10 years ago; the groundwork has been laid, standards have been ratified and base packages/several kernels work perfectly fine on it. The only difference is that ARM is more expensive to license and is less flexible.
> Only the base RISC V is guaranteed thanks extensions.
Yeah. Is that a problem? The situation on ARM is equally bad if not worse (frequent iterations end up throwing even relatively recent CPU models under the bus), and the reason why RISC-V divided itself into extensions is so that you didn't have to start from scratch when John RISC decides to add in 3 new floating point instructions. It's a pretty damn good compromise if you ask me, and it certainly doesn't have any bearing on software availability; RISC-V programs run on RISC-V processors. ARM does not have that same liberty.
There are plenty of genuine constraints for RISC-V (the majority of them in the manufacturing/mass production side of things, now), but the majority of these software issues have been solved and taped out years ago.
The problem is dreamers thinking RISC V will be any different than other CPUs in the industry when big players come playing.
LLVM, contributions level at the scale of Linux kernel, C++20 support now lags behind everyone else.
When money comes to play, the rainbows and flowers eventually turn into wall street yuppies.
RISC-V is just an ISA.
Is this actually true? openSUSE is supplied with a shim bootloader apparently signed with Microsoft's keys, allowing the OS to boot on any machine with Secure Boot enabled.
Both Boot Guard and PSB prevent you from modifying the system firmware (and, say, putting Coreboot on there), but because Boot Guard is implemented in the ME, and because the ME is in the chipset, not the CPU, you can take CPUs out of Intel-based systems and transfer them to somewhere else. If you do the same with a PSB-fused AMD, the firmware on the new board won't be signed with the same key and it'll refuse to boot.
None of this technology provides any real way to prevent you from booting Linux. If vendors wanted to do that, they could already just ship firmware that only supported the Windows signing key and didn't let users enroll new keys. They don't need PSP, ME, Boot Guard or PSB to do that.
And given that is firmware, it's worse than that: the manufacturer can with a firmware update remove (that you can't downgrade thanks to all this security bullshit) the possibility to disable secure boot and revoke the keys used by Linux distributions. Reason why I tend to never update the firmware of computers (as to me the firmware is just a bootloader to GRUB that then boots the operating system).
The real thing is, we don't need this kind of security. We don't need ME, PSP, PSB, TPM, and all kind of bullshit. I've never herd of an attack in real life that exploits the boot process. When 99% of computers runs Windows that is full of security vulnerabilities, and nearly half of them even a no longer supported version of Windows, the other half a non updated version because updates are a waste of time.
And, well, you may well have never heard of attacks that would be mitigated by these technologies, but I have. Firmware-based attacks have existed for over a decade, and the Hacking Team leak included a firmware implant targeted at some ThinkPads. Do I think most users need to worry about this? No, I don't, and I don't know that there's enough people who do need to worry about this that it should be the default (I have thoughts on this, I'll write them up later this evening). But to deny that some people do need to worry about this is just inaccurate.
And Microsoft has required secure boot and TPMs on all certified client systems since Windows 8.1. Almost all shipped hardware already has all this functionality. If Microsoft had any interest in being evil here, they've had the opportunity to do so for years.
Anyway! Even if you can't replace the firmware, the secure boot database is in an unprotected variable store, so you can just replace it even if PSB is enabled. You're welcome.
This is a pure cash grab by Lenovo and AMD, not about mitigating attacks.
If this were about platform security for the benefit of the owner, it would not be permanent, nor enabled by default. All this does is create more e-waste and nuke resale value for Lenovo systems and Ryzen CPUs.
Lenovo has been increasingly slimy for years now (I guess everyone forgets that they've been caught distributing spyware in their products multiple times?) and this is just yet another stop on the road.
I hope Lenovo and AMD both get their asses sued.
If it's not permanent then it doesn't work - any plausible mechanism for allowing it to be disabled can be triggered by whoever's replacing your firmware (which makes AMD's approach somewhat bewildering here, given that you can just replace the CPU). But yes, I agree that enabling it by default is probably the wrong approach here.
This is a real argument. While it might make sense for cloud computing for the client to verify system integrity, malware that modifies firmware is not the largest blip on the radar in these times. A good protection is actually the numerous different manufacturers.
I agree, these technologies aren't primarily for security, they are to enforce how devices are used.
Especially if you extend features like remote attestation, it is more about user control than user security.
> If you're a journalist or an activist dealing with governments that have a track record of targeting people like you, it should probably be part of your threat model.
But considering what we know about the NSA, at least Intel's Management Engine is likely backdoored. So any anti-USA journalist/activist has probably to worry about that too. And an even bigger threat is industrial and diplomatic espionage of non-USA companies and countries using these processors.
(Also could be extrapolated to other countries' secret agencies for potential Huawei, Russian processors, if those ever get popular, like Huawei's control over EU's telecommunications.)
There are situations where that kind of security is required, of course, but they are not something that you should worry about if you use the computer to watch YouTube videos and thus I don't think that makes any sense at all to be present on a consumer PC.
Even with a fully encrypted disk with LUKS, someone could replace your boot manager with a tool to capture your encryption key.
For most people this will be a non issue: the cost of such an attack would highly surpass the benefits.
But I suspect some people would be valuable targets for this.
The code is not malicious please do not call it malware. Your computer already has dozens of other chips running proprietary software on them. It's just a normal part of PC components except since a CPU doesn't have a board the chip is built right in.
Usually it's considered game over if an attacker has physical access to your machine.
That exists for the POWER architecture, but unfortunately those cpus are way behind x86 in speed and efficency, at least so far. I expect RISCV will be the same way for quite some time. Maybe someday...
This is EXACTLY what all the major handsets/cellphones have had in them for a very long time.
Carriers required certain side/backdoors into the devices.. which was really a tunnel for LEO/State...
You buy a Toyota, they screw up the floormats, causing a potentially dangerous situation, millions of cars recalled, issue fixed. Volkswagen knows about an intentional 'screwup' (the exhaust cheating), they get caught, class actions, people return cars, get monetary compensation, etc.
You buy an Intel, after Intel knows about a screwup... whoops... here's a software fix that cripples your cpus performance. Whoops, didnt fix everything, disable hyperthreading. Money back? Nope. Any other kind of compensation? Nope.
Same with software.. they put an EULA there, and they're somehow not responsible for anything anymore.
Here, you might lose a functionality that made you buy that computer in the first place, and "whoops".
And regardless, for a class action suit there'd have to be a class, and as usual the vast majority of people buying Lenovo are not aware of this, wouldn't care if they did, or actually consider it a feature; this article is about some Lenovo machines that I think are sold primarily to businesses who would probably like it if the machine couldn't have end users overwrite the OS or fiddle with the hardware.
First, the security argument is nonsense in my opinion. This "feature" only prevents an attacker from flashing a modified, malicious BIOS on to the server.
But: If an attacker manages to flash a new BIOS to your server, you're already lost. That either requires physical access (which is bad), or access to the OOB / BMC / IPMI (which is equally bad, because those usually have a remote KVM feature, so you could e.g. boot the OS into recovery mode)
It does not prevent any other attacks, because you could still swap out the CPU. The servers usually just quietly burn the CPUs, so you wouldn't notice if the CPUs were replaced by an attacker.
Second, this produces a lot of unnecessary e-waste. About 99% of all hardware (except HDDS) from datacenters is sold on the second hand market. Locked CPUs are essentially worthlese, especially if buyers or sellers don't know and throw the CPU away because they think it's defective.
Third, this opens up a MASSIVE attack surface. Imagine if somebody finds a bug im the PSP (Platform Security Processor, a CPU inside the CPU that handles the locking thing amon g other things) and is able to burn arbitrary keys into the CPU. The attacker would randomly generate a key and burn them into the CPU. You could permanently kill an entire datacenter with that within seconds.
Or if somebody manages to write a malicious BIOS version and flash it to servers which usually don't have a locked BIOS. This BIOS version would also burn a random key into the CPU with the same result: You can easily permanently destroy an entire datacenter.
I think this is just AMD's greediness again in the cloak of "improving security"
Nobody is going to care until this happens.
I've worked on a few SuperMicro servers that bundled OOB/IPMI onto the same NIC that is used for the LAN. 1 RJ45, 2 MAC addresses
I will stab the bean-counter that thought this was an OK idea with a fork if I ever meet them.
The goal of AMD's SEV and other features is that the only way to compromise the system is to tamper the wires between the CPU die and the IO die, that all data going outside the CPU die is encrypted, an extra hardware TPM chip module let you MITM the keys being sent to the CPU, having the keys stored in the CPU using fTPM, and never plaintext / keys leave or enter the CPU via PCIe or memory bus.
the "chipset" is literally just a PCIe/USB multiplexer these days, the CPU has no access to external hardware until after the firmware has loaded, the firmware has routines for turning on the memory and memory controller, PCIe etc, I don't think people understand just how utterly useless the CPU is without the firmware.
Damn I bet someone perhaps a state player or a well financed group is able to do this, can't wait to see this happen...But how does anyone burn it remotely?
Heck, bugs like Meltdown and Spectre were found. And exploits on the PSP have already been demonstrated, see here https://github.com/PSPReverse/amd-sp-glitch
BIOS flashing from the OS has been a thing for a long, long time now. Heck my XPS 13 running Linux even gets BIOS updates from apt-get.
> About 99% of all hardware (except HDDS) from datacenters is sold on the second hand market. Locked CPUs are essentially worthlese, especially if buyers or sellers don't know and throw the CPU away because they think it's defective.
And 99% of that hardware is sold together as a unit. It will hamper repair efforts, as the CPU & motherboard are now effectively a single unit, but it does not effectively kill or even significantly harm the second hand market.
> I think this is just AMD's greediness again in the cloak of "improving security"
Intel has this same feature. This almost certainly wasn't done by AMD's "greediness" but rather because major customers, like Lenovo, demanded it. And even as a "greed" argument it's a pretty flimsy one. Nobody is running a datacenter on second-hand hardware anyway, there's no market to cripple there.
Yes, I forgot to add that point. It's also just as bad as the other options, because it means that the attacker has gained root access. Using the vendor locking as a method to remedy this issue (an attacker being able to compromise a servers' BIOS or BMC) is basically just fighting the symptoms, not the root cause (which is that inband updates from the OS for BIOS and BMC are generally a bad idea)
> And 99% of that hardware is sold together as a unit. It will hamper repair efforts, as the CPU & motherboard are now effectively a single unit, but it does not effectively kill or even significantly harm the second hand market.
This is generally not true. 90% of the hardware is sold separately, servers are mostly sold as barebones and CPUs without servers. Some vendors offer custom configurable servers and I know from many that they make the majority of their sales from barebones or single CPUs, not configured or assembled systems.
> Nobody is running a datacenter on second-hand hardware anyway, there's no market to cripple there.
Not hyperscalers, no. But many SMEs / SMBs buy refurbished hardware and running their datacenters on refurbished hardware. With your argument, we could as well say "just toss all server hardware in the bin once it has been decommissioned" which is obviously nonsense, because if there wasn't demand for refurbished server hardware, there wouldn't be a such a big market in the first place. You can assume that at least 95% of decommissioned server hardware (except HDDs, still too many of them are shredded) gets a second or third life.
UEFI capsule updates are triggered by the OS, but don't occur in the OS. The updates are copied to the EFI system partition, and on next reboot the firmware is triggered to apply them. The flashing process involves the firmware verifying a signature on the image before applying it. The reason for this is that the firmware flash is locked down at runtime, and most of it can't be written to outside System Management Mode. Halting the entire OS for long enough to flash the firmware isn't realistic, so it makes more sense to do it in the firmware environment instead. In any case, the net effect is that while, yes, you trigger the update from the OS, the OS itself is unable to directly modify the firmware, and if you try to flash a modified image via the capsule update mechanism the firmware will reject it for having an invalid signature.
No you can't. AMD builds the TPM in to the CPU, with AMD's encrypted memory feature (SEV), in theory you do not have to trust the data center an all.
The CPU boots, loads a verified firmware using PSB, initializes a safe environment in SEV, your entire boot procedure and data is encrypted and safe using FDE and SEV keys stored in the TPM using PCR's.
> An OEM who trusts only their own cryptographically signed BIOS code to run on their platforms will use a PSB enabled motherboard and set one-time-programmable fuses in the processor to bind the processor to the OEM’s firmware code signing key. AMD processors are shipped unlocked from the factory, and can initially be used with any OEM’s motherboard. But once they are used with a motherboard with PSB enabled, the security fuses will be set, and from that point on, that processor can only be used with motherboards that use the same code signing key.
Basically, the CPU once in that mode will only work with the same signing key, and cannot be put on a motherboard from another brand (or potentially another model from the same manufacturer).
Still really concerning to see Lenovo make boneheaded moves like this when they've had one of the better track records for manufacturers.
If you are enthusiast and need a one or two desktops, then probably not. If you need to procure several hundred of them every few months, then probably yes.
What this definitely will do is to affect the market price of these desktops once the lease (or depreciation time) runs out and owner will try to unload them on second hand market.
IIRC, in Intel's case, the chipset has the vendor keys burned into it. This is not an issue, as the chipset is not a part you would remove from the board and use elsewhere.
I've mentioned this elsewhere but they could have just added some way of writing this signature out of band or allow bypassing it via a solder bridge on the top of the package like how SPD works on memory but require a separate interface for writing to it. Requiring a $10 I2C to USB adapter to change the key is not that onerous and it would be simple enough for OEMs to flash whatever they wanted on it and it could still be cleared for resale. For protecting against an APT doing shipment interdiction attacks quite frankly that sounds like a bunch of B.S. as all locking the key on the processor does is require the processor to be swapped out during an attack as well. If someone is going through the effort to intercept hardware in transit to flash custom malicious firmware on it, the cost of swapping the processor as well is not that extreme.
If they're going to keep the strategy of blowing fuses on the CPU die then AMD should be the ones doing it and they should make a vendor specific SKU so that trying to figure out if a CPU is vendor locked or not isn't such a minefield.
It's not their platform after they sell it. We should resist this trend of referring to items as still belonging to their manufacturers, legitimizing their control over them, while we are reduced to mere users, paying for items but not owning them. Let's see how it sounds:
> An OEM who wants to restrict their customers from selling their CPU, or buying one second-hand, will use a PSB enabled..
This would allow an OEM/ODM to segment their offerings by having two or more sets of signing keys. "Oh sorry, that CPU only works in our entry-level offerings. You will need our enterprise-certified AMD CPU for your large server." "But it's the same socket!"
Most computers end up on the dump as one unit anyways. I've built a few computers in my time but never used an old CPU from one.
And especially not one with that form factor that I probably buy as a wardrobe homelab purpose. I'd compare it to my Asus PN50 that does have a later model Ryzen so it might just make use of this PSB.
Sure it sets an interesting precedent but then again a lot of CPUs in the business are welded to their boards.
And this conspiracy theory of this being like Intel ME, or being used maliciously, is just an exciting answer to what probably has a much simpler explanation, like maybe this is vendor locking their product just like Microsoft Windows has been doing for decades.
I've routinely upgraded drives, graphics cards and memory to give an older system a new lease on life. Usually they're good for a couple of years after that. Essentially the only things remaining where motherboard, CPU and the power supply.
1) It's WAY WAY too easy for someone to not really read this and just press Y to continue, like load setup defaults.
2) There should _not_ be a way of disabling the prompt (the popup even mentions you can do this.)
3) If ever there were a time for a simple math problem (like multiply two numbers and enter the result) to indicate a user had read and understood the prompt, this is it.
I think you are mistaken. I am presuming that the prompt is suggesting that you can disable the PSB security feature (in which case the prompt doesn’t show, which seems very sensible).
Also, it would be complicated for Lenovo too as warranty and consumer laws in every country are different.
Everyone, thanks for the info, once I had a high opinion of the company but it's been going steadily downhill in recent years. Reckon I'd never buy another PC from them again over this nonsense.
It's obvious that this is supposed to limit the second hand server parts market.
https://blog.cloudflare.com/anchoring-trust-a-hardware-secur...
I stand by my orignal statements.
As an aside I'm putting a lot of effort into staying civil; I'd appreciate seeing that effort be a bit more reciprocal.
Which is not the mechanism under discussion.
> The feature was implemented in 2017 the only vendors that are using it are lenovo and dell. With lenovo being the only one using it on lower tier cpus than epyc.
All of the ODMs use PSB in some way (the PSP won't start without it); it's only Lenovo and Dell that use PSB to tie CPUs to certain boards.
It’s what I’d do..,
Of course, no system is perfect so it's not a full guarantee and also there's the impact to the secondary market. But if you're an enterprise leasing these machines you don't care about the secondhand market anyways.
Except that it works the other way. You can put a generic retail processor in the machine -- which will then ruin it by locking it to that vendor.
No customer benefit exists.
Only if they click yes. https://twitter.com/FedsAgainstGunS/status/14734795248054927...
I've permanently lost trust in them after they decided to include malicious root certificates in their systems.
There's a saying about how the best way to make people unware of what freedoms they're losing is to ensure they never had freedom in the first place.
Irrational opposition like that makes it much harder to talk about what's actually important, such as PSB/PSP, without getting lumped together with the tinfoil crowd.
There's no doubt it "does provide protection against certain attacks", but the thing is WE DON'T CARE. We don't want our freedoms slowly being eroded, we see the edges slowly creeping in, and the best way to do that is to take a strong DO NOT WANT attitude towards any such dubious steps in that direction.
Most people thought Stallman was in "the tinfoil crowd" 20 years ago. Yet his predictions have turned out more correct than not.
Slowly, the frog boils...
> but the thing is WE DON'T CARE
YOU don't care, FTFY.
> Most people thought Stallman was in "the tinfoil crowd" 20 years ago.
Just because some things RMS has said have become true does not mean that other things he has said will. Neither does that truth value carry over to other arguments considered similar.
a company to boycott
I understand from this case that my reasonable course of action is to inform my (non-IT-focused) peers and friends that they should avoid Lenovo by explaining the reason behind it (your device is worth less, since you won't be able to install linux or a Mac Clone!) to them.
What is "locking" in this context?
What is the "AMD PSB" ?
PSB: Platform Security Boot
PSP: Platform Security Processor (a CPU inside the CPU which handles e.g. the key burn in process)
Someone bought some Dell servers with 32-core processors. They upgrade to 64-core processors and have the old 32-core processors. You'd like to buy them to upgrade your servers which have 16-core processors. Sorry, even though the chips are otherwise completely identical, theirs came from a Dell and you have a Lenovo. But hey, you can buy the processors directly from Lenovo for only three times as much money.
You will own nothing, and you will be happy.
Currently you have to trust AMD, the Vendor, and the data center with your data.
The goal of verification of the firmware at such a low level is to eliminate tampering by the data center.
Having another feature like SEV (encrypted memory) combined with this lets you create a secure remote box that is fully encrypted at a very early stage in the boot process.
This reduces the chance of a malicious entity at a data center from tamping with the firmware to exfiltrate your keys.
Other people here are just ignorant and think it's being done purely for profit with no benefit to the end user.