cross-posted from: https://lemmy.sdf.org/post/58764195

I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.

So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.

It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.

  • evenwichtOP
    link
    fedilink
    arrow-up
    1
    ·
    3 days ago

    “Fearmongering” was your response to the hackaday link – which supports my thesis not yours. Now you say it’s fine despite the contradiction with the narrative you try to peddle. You have some cognitive dissonance to sort out.

      • evenwichtOP
        link
        fedilink
        arrow-up
        1
        ·
        3 days ago

        Of course it does. It spotlights the PSP infosec shitshow arising out of the AMD spychips. Also shows that a single individual researcher was able to discover it and w/some collaborators demo the exploit (no nation state actor or nation state budgets needed). You have failed to understand my position at a basic level if you can’t see this.

        • Bane_Killgrind@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 days ago

          AMD’s advice is to upgrade to the ADM PSP driver 5.17.0.0 through Windows Update, or to download AMD Chipset Driver 3.08.17.735. Presumably, this solves the issue by properly zeroing out memory during allocation, as well as freeing up memory properly when its no longer needed.

          Overall, a software fix is enough to solve the issue, and its a vulnerability that lacks some of the scare factor of bigger finds like Meltdown and Spectre from years past.

          Sounds like they have their shit together.

          One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

          • evenwichtOP
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            3 days ago

            One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

            Of course. The wide-scale big picture thesis is that it’s foolish to needlessly add an attack surface to the core of your CPU. To those who are infosec aware already accept that automatically because it follows from basic prevailing well-established principles of the infosec discipline. We don’t need to wait for the attack surface to be exploited before realising that the attack surface exists. In laymans terms, we lock our doors even if we have never been intruded on.

            The infosec uninformed don’t practice security by default. They favor the most convenient decision (to run the fastest chip) and will not consider security in the absence of a specific exploit. The hackaday article gives that. It does nothing to sway experts who already know it’s rock-stupid to needlessly introduce an attack surface. The hackaday article supports my thesis in the face of those who reject fundamental infosec principles.

            Sounds like they have their shit together.

            AMD abandons customers of their older products. AMD only reacted as they did because the defect was found in recent hardware. If you equate the similar mentality that also brings designed obolescence to “having their shit together”, you can only speak from the standpoint of a shareholder. When a serious 0-day emerges on a 10+ year old AMD spychip, it’s foolish to assume AMD will have their shit together and patch it. They will have their shit together only in terms of the corporate bottom line, not to the ethical extent of protecting /all/ their customers.

            There are plenty examples of AMD not having their shit together, such as refusing to patch Spectre on some of their own products. Introducing the spychip in the first place is not “having their shit together” for the demographic of non-corporate consumers.

            • Bane_Killgrind@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 days ago

              Attack surface is reduced with architecture like this. You really don’t know what you are talking about or what problems are addressed with this stuff.

              You still seem to think that other people’s resources are infinite, but this time criticising a corp that should have a duty of care in this regard. Bravo, you are on the right track. So where is the line drawn? Things that haven’t been manufactured since 2005? 2000? Please elucidate what the correct policy should be.

              • evenwichtOP
                link
                fedilink
                arrow-up
                1
                arrow-down
                1
                ·
                edit-2
                2 days ago

                Attack surface is reduced with architecture like this. You really don’t know what you are talking about or what problems are addressed with this stuff.

                Bullshit. You really have no clue what you are talking about. The absence of an attack surface is as small as an attack surface gets. When you add something that can be attacked, you are adding an attack surface that was not there before you added it.

                You still seem to think that other people’s resources are infinite,

                On the contrary, you are the one advocating for resource waste. Omitting the spychip uses far fewer resources both for producing and then customer resources for powering it. Then human resources are wasted for controlling the attacks (because you added an attack surface) and for accidental defects (because you added the unnecessary complexity of closed-source software which ensures there is more code that can go wrong and also simultaneously fewer brains reviewing it).

                It’s not just an extra chip. That chip needs a driver. The driver doesn’t write itself. So that takes resources. And that driver creates another point of failure and attack surface. It also requires resources to maintain that driver. And when AMD disregards their “duty of care” because the chip is too old to be profitable thus drops support, the resources of consumers are wasted dealing with the problem (which they should never have had in the first place).

                but this time criticising a corp that should have a duty of care in this regard.

                You sound like a corporate spokesperson for a chip maker. “Duty of care” entails not subjecting your customer to a needless attack surface. What you fail to grasp is the spychip is for corporate customers, not individuals who do not need a closed-source blob in the core of their CPU. Individuals did not ask for a nanny. We requested a CPU that we control ourselves. Forcing us (individuals) to have a nanny we don’t want is a reckless abandonment of duty.

                • Bane_Killgrind@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 days ago

                  The absence of an attack surface is as small as an attack surface gets.

                  Yes and the things that these chips process used to be processed on the main CPU, relying on software to prevent malicious access.

                  Now the attack surface, which used to be every implementation of every software, is reduced to the implementation of the world separation these chips provide.

                  You still aren’t talking about the technology, you are spouting “common sense” nonsense like new chips using single digit watts of power are less efficient than old chips using dozens of watts of power.

                  Garbage.

                  Edit: again, what is the cutoff? Should they still support procs from 1995? 1990?

                  • evenwichtOP
                    link
                    fedilink
                    arrow-up
                    1
                    arrow-down
                    1
                    ·
                    edit-2
                    1 day ago

                    Yes and the things that these chips process used to be processed on the main CPU, relying on software to prevent malicious access.

                    Rightfully so.

                    Correction to your utter pro-corporate drivel:

                    Now the attack surface, which used to be every implementation of every software, is reduced expanded to the unreachable closed-source implementation that makes consumers dependant on a corporate of the world separation with an imbalance of power these chips provide subject consumers to.

                    You still aren’t talking about the technology

                    The thread was originally about e-waste of technology. Your thread crap has discarded the e-waste discussion, so of course I am talking about technology. This thread branch is about avoiding undisclosed opaque technology with an attack surface we don’t need.

                    , you are spouting “common sense” nonsense like new chips using single digit watts of power are less efficient

                    The spouting of nonsense comes when you neglect to make a meaningful comparison that actually reveals the waste of the spychip. You can’t hide the spychip’s waste by choosing processors of different effeciencies from different time periods.

                    than old chips using dozens of watts of power.

                    You missed the link about new machines still using a 2013 pre-spychip because the TDP is 17w. But I guess it hardly matters when you’re trying to make a dishonest comparison anyway to conceal waste.

                    Edit: again, what is the cutoff? Should they still support procs from 1995? 1990?

                    If it’s a closed-source spychip, it should be supported for as long as the chip maker exists. And when they go under, they should be forced to disclose the source code. If they don’t like that, they should quit making the spychips. If they are ruined and sink because they failed to support their crippled support-needy garbage, then rightfully so.

                    If it’s not a spychip, it needs no support from the maker apart from documentation, which should always be available as long as the chip maker exists. And thereafter available on archive.org.