I’m in the rabbit hole trying to work out which AMD CPUs are spychip free. It’s non-trivial and looks like we cannot draw a line and simply say all successor chips released after that line are spychips.

One rabbit hole begins with this 2014 AMD family: “Kaveri” (2014) & “Godavari” (2015)

Which states:

“Integrated custom ARM Cortex-A5 co-processor[47] with TrustZone Security Extensions[48] in select APU models, except the Performance APU models.[49]”

This implies there are some Kaveri or Godavari CPUs that are spychip free. Footnote 49 links to this AMD sales pitch. Worth noting that someone on the coreboot project also found those same sales presentation slides interesting:

https://github.com/mikebdp2/coreboot-related/tree/master

Page 12 was cited in the footnote, which shows a claim that “Carrizo” (which describes a whole family of 2016 processors) is the “1st ARM TrustZone Capable Performance APU”. Yet 2013 is widely believed to be when the garbage came. Apparently the keyword is “APU”. If true, then pre-Carrizo (2016) APUs are spychip free, while conventional CPUs were enshitified as early as 2013.

But there could be a nastier nuance here. What is a “performance APU”? Is the word performance important in this context? If yes, then earlier non-performance APUs (whatever that may refer to) could be spy chips.

Anyway, by extension of page 12 info, some would conclude that all the APUs listed for “Kaveri” (2014) & “Godavari” (2015) are spychip free (that is, the processors which include an embedded GPU), but not the CPUs.

No one has mentioned page 22 of that presentation, which states that an AMD A9-9410 which is based on “Stoney Ridge” (2016) does not have “trusted execution security”, which implies no PSP IIUC. Do I understand correctly? Does this mean a 2016 chip based on Excavator does not have the PSP despite Carrizo having it in APUs a year prior? Update: the slide must be wrong. This page asserts that models 60h and later within the 15h family are spychips. That includes Excavator and thus Stoney Ridge, unless there is another exception that’s undocumented.

This article claims we must nix Kaveri and look for prior releases. OTOH, this article claims Kaveri is safe.

I am tempted to conclude that the APU half of Kaveri is safe. But there is another contradiction in Wikipedia. The Kaveri mobile processors are all APUs, and yet Wikipedia claims they are all: “Integrated custom ARM Cortex-A5 co-processor[47] with TrustZone Security Extensions[48]”. Does this go back to the keyword “performance” APUs? Are mobile APUs regarded as non-performance APUs?

(update) We can see that “ro” includes the conventional CPUs within Kaveri as spychip-free:

Steamroller/Kaveri (Desktop APUs)
Athlon X2 450 (2x 3,5 Ghz, 65W)
Athlon X4 840 (4x 3,1 Ghz, 65W)
Athlon X4 860K (4x 3,7 Ghz, 95W)
Athlon X4 870K (4x 3,9 Ghz, 95W)
Athlon X4 880K (4x 4,0 Ghz, 95W)
FX-770K (4x 3,5 Ghz, 65W)

But that’s likely a mistake per the sales slide and exception in the Wikipedia footnote. I would not trust those chips. Actually it’s not that clear cut. Excluding the APUs in that group as PSP does give cause to assume the CPUs have a PSP. Wikipedia lacks a source that attributes any chips in that section to having a PSP. We also don’t know what drives the claim that Kaveri is unsafe in this research… perhaps someone trusting Wikipedia.

(update) Another dicey set of chips: Kabini

If we have confidence in page 12 of the AMD sales slides, then we would trust the performance APUs among the “Kaveri” (2014) & “Godavari” (2015) families, which are based on Steamroller (15h gen3). So naturally we would be tempted to trust older performance APUs like the 2013 ones codenamed “Kabini”.

The wikipedia section for Kabini neglects to mention trustzone, which adds to our confidence. However, the microarchitecture for these chips is Jaguar, which is 16h. 16h is newer than 15h, and rightfully distrusted by “ro”, who spotlights this page which states:

“Please note that Family 16h and Family 15h-Models60h and later contain a PSP but it does not perform the memory initialization.”

Wikipedia claim unsubstantiated – leaves outstanding question on Kaveri. Any mobile APU Kaveri owners reading this?

Since Kaveri is based on Steamroller, which has not been documented to include spy chips, I see no evidence for the Wikipedia claim in this section that there is a PSP. There is footnote 47 and 48, but those are vague. The sources say nothing about which specific chips will have the PSP.

I suppose we need someone with a laptop with one of those mobile APUs in the Kaveri family to try to test or detect a PSP and report back.

It would also help if someone with Wikipedia access would add a citation needed tag.

Update: Corporate boot lickers are ironically thick in this forum

Street-wise consumers phrase the question this way:

“Is there credible evidence that the hardware will serve my best interests as an individual non-corporate user?”

Corporate spokespeople, boot lickers, and convenience¹ addicts spin the question this way:

“Is there credible evidence that an attack has be demonstrated?”

There are two things going on here:

① First they want to do away with the prospect that the closed-source blob does anything intentional that works against the interest of the consumer who owns the CPU. The bias downplays malignment of interests. They shrink the focus to attacks.

② Then they play a game with burden of proof, suggesting the consumer has the burden of proof.

Wise consumers don’t accept that burden. It’s the seller’s burden. It’s the seller’s burden to show us the code. It is the seller’s burden to obtain a 3rd-party audit by infosec researchers. Sellers who neglect that burden can fuck off. AMD has not earned the business of smart consumers post 2013.

Wise consumers are increasingly in short supply. This is why the marketplace is becoming increasingly enshitified. And ultimately in part why retrocomputing is interesting to the small demographic of wise consumers.

(1) Convenience addicts being those who cannot resist fast and cheap - a demographic we don’t expect to find in !retrocomputing@lemmy.sdf.org.

  • evenwichtOP
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    1 day ago

    But, for your mental and social health, you should really maybe take a step back, clear your mind, and read some of the things that are here.

    That advice is good for the pragmatist who does not give a shit about ethics.

    The horse your riding on is so high, I’m not even sure you can see the grass, let alone touch it.

    This is not how you convince ethical consumers to switch to the pragmatic self-fulfilling path. Ethical consumers do not patronize enshitifiers. Not taking the higher moral ground is one decision but then it’s a bit extra perverse to frame ethical consumption as something that is done “on a high horse”.

    The intentional use of inflammatory language, the not actually answering a question,

    The question was irrelevant threadcrap. You need to lower your expectations when you bring uncivil commentary.

    and the fact that you’re about a hop skip and jump from actually saying “DO YOUR OWN RESEARCH!”

    It’s more like: GET YOUR OWN THREAD.

    You are only a stone’s throw from a Truther or other fun conspiracy nut.

    This is exactly how a layperson (aka “normie”) perceives infosec practicioners. If someone groking infosec comes off as “paranoid”, it’s more an indication of the audience. We opt for security by default and require justified cause to make a compromise. The normie mindset is the reverse of that: prioritize convenience by default while requiring a justified reason to take a security-driven decision or to implement a street-wise security practice.