cross-posted from: https://lemmy.sdf.org/post/58764195

I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.

So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.

It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.

  • evenwichtOP
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    15 hours ago

    Man this is some fearmongering.

    The evidence is in front of you. Hackaday.com is publishing facts. These facts do not make you fearful yet you call them fearmongering.

    Dude you are more likely to get viruses and exploited running the older hardware.

    Nonsense. Vulns in the older hardware are mostly of the known variety. New hardware is rich in the unknown variety of vulns, which by their nature you don’t know about and cannot control for.

    I understand that vulnerabilities pop up, but at least the within a decade recent stuff gets patched.

    And new vulns get introduced. Even the patches themselves bring new vulns.

      • evenwichtOP
        link
        fedilink
        arrow-up
        1
        ·
        4 hours ago

        “Fearmongering” was your response to the hackaday link – which supports my thesis not yours. Now you say it’s fine despite the contradiction with the narrative you try to peddle. You have some cognitive dissonance to sort out.

          • evenwichtOP
            link
            fedilink
            arrow-up
            1
            ·
            3 hours ago

            Of course it does. It spotlights the PSP infosec shitshow arising out of the AMD spychips. Also shows that a single individual researcher was able to discover it and w/some collaborators demo the exploit (no nation state actor or nation state budgets needed). You have failed to understand my position at a basic level if you can’t see this.

            • Bane_Killgrind@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 hours ago

              AMD’s advice is to upgrade to the ADM PSP driver 5.17.0.0 through Windows Update, or to download AMD Chipset Driver 3.08.17.735. Presumably, this solves the issue by properly zeroing out memory during allocation, as well as freeing up memory properly when its no longer needed.

              Overall, a software fix is enough to solve the issue, and its a vulnerability that lacks some of the scare factor of bigger finds like Meltdown and Spectre from years past.

              Sounds like they have their shit together.

              One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.