I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.
So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.
It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.
I see your point, but you’re being such a dick in this thread that I’m kind of happy you didn’t get what you wanted and I kind of hope you never do.
I scrolled for a bit and, welp.
Imagine being like that without understanding that you’re the one lacking essential behaviors for pleasant human interaction.
It’s not about me. I already found a pre-spychip laptop at a street market for under $£€ 10. It’s about global e-waste of useful goods and the ignorance driving it. Ignorance that is thick as we can see from an absence of basic infosec principles and people being conditioned to lick boots without questioning the ethics of patronising anti-consumer suppliers.
Ignorance is not in itself a big problem. It can be corrected if someone is willing to learn. And I can accept arrogance if it’s logically sound and factually correct. But ignorance coupled with pretentious arrogance is a bit intolerable. I don’t give a shit about the egos of such thread crapping responders.
pretentious arrogance is
The irony of you of all people calling this out…
By spychip are you referring to IME and PSP? Chips that old are going to have security holes larger than a CEO’s ego. Those chips will be vulnerable to Spectre and Meltdown. Iirc from the fallout of those CVEs, only AMD bothered to patch chips that went back to 2011
“Meltdown affects Intel x86 microprocessors, IBM Power microprocessors,[1] and some ARM-based microprocessors”
I don’t see AMD on that list. Do you?
“At the time of disclosure (2018), this included all devices running any but the most recent and patched versions of iOS,[5] Linux,[6][7] macOS,[5] or Windows.”
So this vuln can be fixed by patching OS kernels, and your reaction is to switch to a CPU that runs embedded closed-source software controlled by a corporate third party who decides what is authorized to execute on your own system? You can fix the problem with or without being nannied. I’ll take the latter.
Spectre affected “All pre-2019 microprocessors”. So no, the spy chip did not protect you. Intel injected the spychip from 2008 forward and AMD did it from 2013 forward.
More generally, it’s not smart infosec to introduce extra complexity. It’s profoundly naive to stick a big attack surface in the core of your CPU. I think it’s quite well established that vulns exploit defects, and defects are proportional to complexity. Signing up for a closed source blob in the core of your processor is adding complexity that’s far from wise.
The /chase the shiny/ mentality (of “latest is greatest!”) neglects the fact that you sign up for the worst kind of vulns – the unknown variety. With old gear the vulns are more of the known variety, which you have a fighting chance of controlling for.
I don’t see AMD on that list. Do you?
Lashing out at me was unnecessary. I was pointing out that there are 2 catastrophic vulnerabilities that are guaranteed to be present in every chip that meets your criteria.
I’m not defending the IME or the PSP. The most generous thing I can say about them is that they are unnecessary. I’m pointing out that the chips that you want to use have been unsupported for so long that they have catastrophic vulnerabilities that have never even been attempted to be patched. There are more catastrophic vulnerabilities than just Spectre and Meltdown.
Lashing out at me was unnecessary.
It was an attack on your bullshit. Not on you personally.
I was pointing out that there are 2 catastrophic vulnerabilities that are guaranteed to be present in every chip that meets your criteria.
And I was pointing out that you are wrong.
I’m pointing out that the chips that you want to use have been unsupported for so long that they have catastrophic vulnerabilities that have never even been attempted to be patched.
You are advocating for chips that are /more/ vulnerable, not less. You are advocating for chips with a much larger attack surface which brings copious unknown vulns. Overall, you are giving poor advice from an infosec standpoint. It is easier to secure a simple known thing than a complex unknown thing.
There are more catastrophic vulnerabilities than just Spectre and Meltdown.
I’m listening.
And I was pointing out that you are wrong
No, you weren’t. You were being pedantic. AMD will have Spectre. Intel will have Spectre and Meltdown. 2 vulnerabilities.
You are advocating …
No, I wasn’t. Stop putting words in my mouth. Unless you know how to write microcode, I have serious doubts that you are capable of successfully patching the vulnerabilities on those chips.
Do whatever you want. I don’t care.
No, you weren’t. You were being pedantic.
If you don’t like the facts, what more is there to say? The facts failed to support your claims. If you will not let the facts shape your world view, then it’s on you to go off and find different facts.
No, I wasn’t. Stop putting words in my mouth.
Advocating for only running “supported” chips is inherently contempt for old hardware. (But note you said that apparently without knowing about the 15h.org project).
Unless you know how to write microcode, I have serious doubts that you are capable of successfully patching the vulnerabilities on those chips.
How are you still failing grasp this? The fix was made. And it was done in the kernel without writing microcode. You’ve been told this already. You did not counter it yet to still failed to absorb it. And now you try recycling defeated arguments. You don’t even have to patch Meltdown on chips unaffected by Meltdown (AMD). The spychip failed to protect from both Meltdown and Spectre.
Patching is not the only way to control for a vuln. I am not going to give you the whole infosec discipline here in this thread. There are many ways to controlling for a vuln apart from patching. Depending on your threat model and use cases, there may be no need to do any control. The 15h.org project is another kind of control. Air gapping is another. Detecting the malicious code is another.
You act like you’re the only one that understands information security. I took a security class for my computer science degree too. Productive conversation cannot be had when you strut around arrogantly dismissing everyone that disagrees with you.
The fix was made. And it was done without writing microcode.
Spectre was a microcode patch. Meltdown was a kernel patch, so in firmware. Only AMD bothered to fix chips that fit within your timeframe. The fix has not been made for the chips you want to use.
Patching is not the only way to control for a vuln
You aren’t going to stop branch prediction with clever tricks. These are hardware level flaws. Patching is the only way to completely mitigate these flaws.
dismissing everyone that disagrees with you.
What’s being dismissed is irrelevant facts. You continue (for a 3rd time) to still fail to grasp the fact that Meltdown was not found to affect AMD chips. It’s wholly irrelevant.
Spectre was a kernel patch, so in firmware.
Those are two different things. There was a firmware patch. And separately there was a kernel mitigation. You don’t need both.
Only AMD bothered to fix chips that fit within your timeframe. The fix has not been made for the chips you want to use.
You mean AMD’s f/w patch was not made. Yet you’ve been told about the 15h.org project. If you absorbed that, then citation needed that Coreboot fails to mitigate. In the absence of Coreboot, the os mitigation was implemented in linux. So you’re pushing a bullshit problem.
They likely are only selling what people want to buy. Just the way the world works. It tends to cost money to send them some where they actually want those.
Sadly the same thing happens with retro Gear I want. History just being erased due to capitalism.
Recycling the components for the metals and other bits in them is a good use though.
Selling computer equipment to rife with security concerns and compatibility issues isn’t charity
Correction:
They likely are only selling what
peoplethe mainstream masses want to buy on a daily basis.Smart consumers are marginalised. Just as they are with most of the ensitified market.
Correction:
Just the way
the worldcapitalism works.But we are talking about a charity. I was not talking about a profit-driven company.
It tends to cost money to send them some where they actually want those.
Not for pick-ups (which would be my case). As it stands, they already have to ship them for destruction and THAT costs money. They are not willing to maintain a list of hardware sought by people. Until we pull levers and twist arms using activism to get a registry of parts sought and who to contact. The price I would pay exceeds the cost of paying their staff to enter a database record and cross-reference what arrives.
You’ve made the poor assumption that many do: that the market is already maximally efficient and that everyone is already operating intelligently. They are not. The story of Michael Dell proves that.
But we are talking about a charity. I was not talking about a profit-driven company.
A charity still needs to turn a profit or they won’t be a charity for long. The point is that they make enough money from reselling these things that they can offer some sort of service.
And by people I only mean the ones shopping there. Not the “mainstream masses”. Its a charity shop, not Microcenter or Amazon.
A charity still needs to turn a profit or they won’t be a charity for long.
Nonsense. By law, they /must/ break even.
The point is that they make enough money from reselling these things that they can offer some sort of service.
That’s only partially true. If the sales activity is unrelated to the mission, then the sales must support something else that supports the mission. If the mission is environmental, or privacy, or pro-consumer, or human rights (autonomy specifically), or free software, then your claim falls apart. They can even lose money in an activity that promotes their mission as long as their other activities offset the loss.
And by people I only mean the ones shopping there. Not the “mainstream masses”.
It’s one in the same. I would shop there if they had what I wanted. But I won’t shop there when they don’t have what I’m after – as they are only targeting the mainstream masses. They had to turn me away because I was not in the mainstream masses they are targeting. For the same reason (targeting mainstream masses), they quit selling machines with linux.
Its a charity shop, not Microcenter or Amazon.
Exactly. It’s bizarre that you can realize this while simultaneously rely on them behaving like a Microcenter or Amazon.
I don’t think you know what you are talking about with non-profits. I used to have one for my reddit socials group. I founded it and was the president/ceo for about 8 years. I can tell you right now, you can definately run it as a for profit. In fact, there is a specific dollar amount you can profit off it. Every year when I submitted financial documents to the state I had to show generally (high level only, not specific) every dollar that came in or out, but they didn’t care about where it came from or where it went to. The only real question was if I had over exactly $1 million in profit. Obviously I never did, but if I did there would simply be a slightly different set of rules on what I would have to do with it or how to declare it. If I had a non-profit that sold computers and grossed $999,999 per year, then paid myself or banked everything left over, then I am still a perfectly legal non-profit and don’t need to report any details on my finances other than general numbers.
And as far as financials related to the mission? Literally nothing stopping me from spending it on whatever I feel like. If my mission is slinging used computers to help kids with cancer- i can buy a fucking yacht with all my computer sales money under the non-profit then donate $1 to st.judes. This is why millionares and billionaires love to found their own charity and wash money through it. The rules are so gray.
Want to know the most common bullshit with non-profits if you still don’t believe me? Look up Equine Therapy non-profits. It is how you make your horse(s), stable, and pasture all sheltered as a non-profit. Then once a year you have some nondescript, unverified, person ride one of your horses and count it as your charity event to justify the existence. I know so many people who own horses who do this bullshit to help cover the cost of owning them. And most of these people aren’t even that rich, just well off. And again, totally legal.
None of this obviates my thesis. A profit limit of $999,999 in your country reflects a buffer for ops. That’s has no material relevance here. Nor does it support the other Cloudflare user who claimed the charity activity of selling old machines is not viable. To claim that it’s not possible to sell old machines (even at a loss) and yet sustain, this makes it hard to believe you really know how non-profits work – assuming that is your stance. Otherwise, what’s your point?
Indeed it is well known that non-profits have countless angles for abuse. People like Peter Thiel and other right-wing pricks notoriously abuse the non-profit charity structure. That’s mostly irrelevant but to the extent that it’s relevant it actually supports my thesis nonetheless. An abuser who funds a yacht from charity work obviously has enough slack money to sell some old machines, or even pay someone to take them.
Nonsense. By law, they /must/ break even.
They aren’t required to break even. There is no law prohibiting or preventing them from losing money.
The second smartest thing to do is to have someone you know / trust offer to buy the machines from the charity before they are destroyed (by getting those forwarded away from them, for example), assuming they still get some. Consider, you have a potential good, actionable source to nab good hardware.
The smartest is to get charity policy changed, but that’s more of a hassle.
I’m sitting on my Pentium-M’s, they’ll be worth in gold one day.
I appreciate the spirit of your concern.
How old do you have to go before you don’t consider them spychips?
2013 for AMD. 2008 for Intel.
What’s a spychip?
Microprocessors embedded within a microprocessor which either facilitate remote access or impose closed source software.
- https://www.intel.com/content/www/us/en/support/articles/000097447/technologies.html
- https://web.archive.org/web/20250920141935/https://www.franksworld.com/2025/09/18/the-intel-backdoor-nobody-can-remove-not-even-you/
- https://consumerrights.wiki/w/AMD_Platform_Security_Processor
- https://hackaday.com/2021/10/01/flaw-in-amd-platform-security-processor-affects-millions-of-computers/
Sounds like most PCs today tbh, bar a few niche machines.
Sounds like most PCs today
Bingo. Avoiding it requires either an old machine or an IBM Power 9 chip (which is relatively modern).
Are they watching me watch porn?
Not the chips I am referring to. But these will:
https://slrpnk.net/post/42012494
Watch out for them.




