I’m in the rabbit hole trying to work out which AMD CPUs are spychip free. It’s non-trivial and looks like we cannot draw a line and simply say all successor chips released after that line are spychips.

One rabbit hole begins with this 2014 AMD family: “Kaveri” (2014) & “Godavari” (2015)

Which states:

“Integrated custom ARM Cortex-A5 co-processor[47] with TrustZone Security Extensions[48] in select APU models, except the Performance APU models.[49]”

This implies there are some Kaveri or Godavari CPUs that are spychip free. Footnote 49 links to this AMD sales pitch. Worth noting that someone on the coreboot project also found those same sales presentation slides interesting:

https://github.com/mikebdp2/coreboot-related/tree/master

Page 12 was cited in the footnote, which shows a claim that “Carrizo” (which describes a whole family of 2016 processors) is the “1st ARM TrustZone Capable Performance APU”. Yet 2013 is widely believed to be when the garbage came. Apparently the keyword is “APU”. If true, then pre-Carrizo (2016) APUs are spychip free, while conventional CPUs were enshitified as early as 2013.

But there could be a nastier nuance here. What is a “performance APU”? Is the word performance important in this context? If yes, then earlier non-performance APUs (whatever that may refer to) could be spy chips.

Anyway, by extension of page 12 info, some would conclude that all the APUs listed for “Kaveri” (2014) & “Godavari” (2015) are spychip free (that is, the processors which include an embedded GPU), but not the CPUs.

No one has mentioned page 22 of that presentation, which states that an AMD A9-9410 which is based on “Stoney Ridge” (2016) does not have “trusted execution security”, which implies no PSP IIUC. Do I understand correctly? Does this mean a 2016 chip based on Excavator does not have the PSP despite Carrizo having it in APUs a year prior? Update: the slide must be wrong. This page asserts that models 60h and later within the 15h family are spychips. That includes Excavator and thus Stoney Ridge, unless there is another exception that’s undocumented.

This article claims we must nix Kaveri and look for prior releases. OTOH, this article claims Kaveri is safe.

I am tempted to conclude that the APU half of Kaveri is safe. But there is another contradiction in Wikipedia. The Kaveri mobile processors are all APUs, and yet Wikipedia claims they are all: “Integrated custom ARM Cortex-A5 co-processor[47] with TrustZone Security Extensions[48]”. Does this go back to the keyword “performance” APUs? Are mobile APUs regarded as non-performance APUs?

(update) We can see that “ro” includes the conventional CPUs within Kaveri as spychip-free:

Steamroller/Kaveri (Desktop APUs)
Athlon X2 450 (2x 3,5 Ghz, 65W)
Athlon X4 840 (4x 3,1 Ghz, 65W)
Athlon X4 860K (4x 3,7 Ghz, 95W)
Athlon X4 870K (4x 3,9 Ghz, 95W)
Athlon X4 880K (4x 4,0 Ghz, 95W)
FX-770K (4x 3,5 Ghz, 65W)

But that’s likely a mistake per the sales slide and exception in the Wikipedia footnote. I would not trust those chips. Actually it’s not that clear cut. Excluding the APUs in that group as PSP does give cause to assume the CPUs have a PSP. Wikipedia lacks a source that attributes any chips in that section to having a PSP. We also don’t know what drives the claim that Kaveri is unsafe in this research… perhaps someone trusting Wikipedia.

(update) Another dicey set of chips: Kabini

If we have confidence in page 12 of the AMD sales slides, then we would trust the performance APUs among the “Kaveri” (2014) & “Godavari” (2015) families, which are based on Steamroller (15h gen3). So naturally we would be tempted to trust older performance APUs like the 2013 ones codenamed “Kabini”.

The wikipedia section for Kabini neglects to mention trustzone, which adds to our confidence. However, the microarchitecture for these chips is Jaguar, which is 16h. 16h is newer than 15h, and rightfully distrusted by “ro”, who spotlights this page which states:

“Please note that Family 16h and Family 15h-Models60h and later contain a PSP but it does not perform the memory initialization.”

Wikipedia claim unsubstantiated – leaves outstanding question on Kaveri. Any mobile APU Kaveri owners reading this?

Since Kaveri is based on Steamroller, which has not been documented to include spy chips, I see no evidence for the Wikipedia claim in this section that there is a PSP. There is footnote 47 and 48, but those are vague. The sources say nothing about which specific chips will have the PSP.

I suppose we need someone with a laptop with one of those mobile APUs in the Kaveri family to try to test or detect a PSP and report back.

It would also help if someone with Wikipedia access would add a citation needed tag.

Update: Corporate boot lickers are ironically thick in this forum

Street-wise consumers phrase the question this way:

“Is there credible evidence that the hardware will serve my best interests as an individual non-corporate user?”

Corporate spokespeople, boot lickers, and convenience¹ addicts spin the question this way:

“Is there credible evidence that an attack has be demonstrated?”

There are two things going on here:

① First they want to do away with the prospect that the closed-source blob does anything intentional that works against the interest of the consumer who owns the CPU. The bias downplays malignment of interests. They shrink the focus to attacks.

② Then they play a game with burden of proof, suggesting the consumer has the burden of proof.

Wise consumers don’t accept that burden. It’s the seller’s burden. It’s the seller’s burden to show us the code. It is the seller’s burden to obtain a 3rd-party audit by infosec researchers. Sellers who neglect that burden can fuck off. AMD has not earned the business of smart consumers post 2013.

Wise consumers are increasingly in short supply. This is why the marketplace is becoming increasingly enshitified. And ultimately in part why retrocomputing is interesting to the small demographic of wise consumers.

(1) Convenience addicts being those who cannot resist fast and cheap - a demographic we don’t expect to find in !retrocomputing@lemmy.sdf.org.

      • Mnem667@sh.itjust.works
        link
        fedilink
        arrow-up
        7
        ·
        1 day ago

        Yeah. I am just curious about the implications. There’s been a couple of vulnerabilities reported and patches, but anything that would indicate “spy chip”? I would normally assume some security researcher would have said something by now.

        • hexagonwin@lemmy.today
          link
          fedilink
          arrow-up
          7
          ·
          1 day ago

          (afaik) it has the privilege to operate as a backdoor transparent from the os because it operates on low level like intel me

    • evenwichtOP
      link
      fedilink
      arrow-up
      2
      arrow-down
      6
      ·
      edit-2
      14 hours ago

      “Spy chip” is not a claim. It’s nomenclature. I am referring to the PSP. You don’t have to call it a “spy chip” if you don’t want. You can call it “friendly alternate control mechanism”, or “helpful nanny”, if you want. Call it “trustworthy proprietary closed-source security oversight guardian angel”, if you want. Or how about “WINchip” for Well-Intenioned Nanny? Whatever you choose to call it, you don’t need a “credible source” for whatever word or phrase you choose to use. “Spychip” has the prevailing nomenclature of those who prefer to be in control of their own property, which encapsulates a rejection of PSP, IME, Trustzone, and the like. And even more broadly, sometimes refers to clipper chips, or RFID, depending on context.

      From there, what is a credible source for a word or phrase, when the language is English? It’s not like Academy Français, which officially recrognizes words in the French language under the authority of the French government. English is more chaotic. If a lot of people are using a word or phrase, journalists will use it. If journalists are using a word frequently, maybe Oxford dictionary or Marriam Webster will add it to their dictionary, if the feel like it. If you are American, you may not consider Oxford dictionary credible. And if you are British, you may not consider Webster’s dictionary credible.

      I doubt any dictionary has added the term spychip. Unlike the word “piracy” of the non-high-seas hijacking variety, where various dictionaries are happy to equate the peaceful sharing of information/deas with “piracy” (rape, theft, randsacking, pillaging, etc).

      • Mnem667@sh.itjust.works
        link
        fedilink
        arrow-up
        7
        arrow-down
        4
        ·
        19 hours ago

        Well, my apologies for not being hip to the lingo. I appreciate your enthusiasm, but damn. I just wanted to know if there was some nefarious thing about the PSP that I had not read about yet.
        Instead I get a a diatribe of self indulgent sarcasm.
        So I suppose the answer is “no”. It’s just a scary black box that could potentially be a source of some data collection or used as a backdoor, but no one in the last 8 years has published any such papers.
        Now I am aware, and my curiosity is sated.

        • evenwichtOP
          link
          fedilink
          arrow-up
          1
          arrow-down
          5
          ·
          edit-2
          3 hours ago

          The official reason for the intel ME (the intel version of AMD’s PSP which hit in 2008) is so corporations could do some remote management ops on their corporate laptops, and so malware is hindered if it tries to insert itself into the bootstrap and so employees cannot install their own OS or whatever. Of course there is nothing controversial about those scenarios. Something like 99% of intel’s clientel is corporate. The individual human beings who buy personal computers for their own non-business activity are in the 1% that mean nothing to intel. So of course their needs can be neglected as far as Intel is concerned. Only the corporate consumer matters to the bottom line.

          Corporations don’t give a shit about closed-source software. To them, accountability is paramount. Closed-source increases accounatibility on the supplier. If the closed-source software does something nasty to them, managers can point fingers. Corporate lawyers can sue. But if some shitty proprietary closed-source software is used against the interest of some individual, no one gives a shit. We can be marginalised. Hence why some of us like our FOSS. Transparency and control is more important than accountability to individual human beings without lawyers on retainer. I don’t want some closed-source garbage at the hand of some remote corporation deciding what bootstrap is “authorized” on my own property. OTOH if you run MS Windows, none of this matters to you.

          We have lost sight over who serves who in the customer-supplier relationship. And now we have a fuck-ton of consumers who are okay with buying something they do not control, like a remotely controllable hidden core. I would have to be extremely desperate to buy a black box laptop. For now, my pre-2008 intel (non-spychip) performs well enough for my needs. When that changes, I believe a 2013 spychip-free AMD will suit my needs for another 10 or 20 years. Only then will I face having to cross the bridge where I lick the boots of an anti-consumer supplier. And perhaps by then we will have a viable open hardware for-the-people option.

          Worth noting that the IBM power9 chip (or something like that) is both reasonably modern and also spychip free. But last time I checked you cannot get it in a laptop. It’s a costly processor for servers only. But in 10 or 20 years, maybe 2nd-hand IBM power9 or whatever will be cheap enough. I don’t foresee having to feed the marketplace of anti-consumer garbage anytime soon – at least not w.r.t. laptops. But if I am buying a washing machine, then indeed I am fucked. It’s getting harder to find a washing machine that is not anti-consumer even 2nd-hand.