cross-posted from: https://lemmy.sdf.org/post/58764195

I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.

So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.

It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.

@evenwicht@lemmy.sdf.org
creator
link
fedilink
0
edit-2
5d

The evidence shows it takes a higher level of knowledge and more specialized knowledge to exploit the thing

I see no evidence from you here. Yes, it requires a big brain. But it does not require a nation state as you originally claimed (which is a composition of many well-paid big brains dedicated to the work professionally). Cybercriminals are not limited to nation states. They operate in all scales, some organised, some not. The evidence shows that a bug in a driver for the spychip is all it takes:

https://hackaday.com/2021/10/01/flaw-in-amd-platform-security-processor-affects-millions-of-computers/

Man this is some fearmongering.

Dude you are more likely to get viruses and exploited running the older hardware.

I understand that vulnerabilities pop up, but at least the within a decade recent stuff gets patched.

Man this is some fearmongering.

The evidence is in front of you. Hackaday.com is publishing facts. These facts do not make you fearful yet you call them fearmongering.

Dude you are more likely to get viruses and exploited running the older hardware.

Nonsense. Vulns in the older hardware are mostly of the known variety. New hardware is rich in the unknown variety of vulns, which by their nature you don’t know about and cannot control for.

I understand that vulnerabilities pop up, but at least the within a decade recent stuff gets patched.

And new vulns get introduced. Even the patches themselves bring new vulns.

Completely ridiculous. You are fearmongering. Hackaday is fine.

“Fearmongering” was your response to the hackaday link – which supports my thesis not yours. Now you say it’s fine despite the contradiction with the narrative you try to peddle. You have some cognitive dissonance to sort out.

The article doesn’t actually support your “thesis”

@evenwicht@lemmy.sdf.org
creator
link
fedilink
1
edit-2
4d

Of course it does. It spotlights the PSP infosec shitshow arising out of the AMD spychips. Also shows that a single individual researcher was able to discover it and w/some collaborators demo the exploit (no nation state actor or nation state budgets needed). You have failed to understand my position at a basic level if you can’t see this.

AMD’s advice is to upgrade to the ADM PSP driver 5.17.0.0 through Windows Update, or to download AMD Chipset Driver 3.08.17.735. Presumably, this solves the issue by properly zeroing out memory during allocation, as well as freeing up memory properly when its no longer needed.

Overall, a software fix is enough to solve the issue, and its a vulnerability that lacks some of the scare factor of bigger finds like Meltdown and Spectre from years past.

Sounds like they have their shit together.

One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

@evenwicht@lemmy.sdf.org
creator
link
fedilink
1
edit-2
4d

One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

Of course. The wide-scale big picture thesis is that it’s foolish to needlessly add an attack surface to the core of your CPU. To those who are infosec aware already accept that automatically because it follows from basic prevailing well-established principles of the infosec discipline. We don’t need to wait for the attack surface to be exploited before realising that the attack surface exists. In laymans terms, we lock our doors even if we have never been intruded on.

The infosec uninformed don’t practice security by default. They favor the most convenient decision (to run the fastest chip) and will not consider security in the absence of a specific exploit. The hackaday article gives that. It does nothing to sway experts who already know it’s rock-stupid to needlessly introduce an attack surface. The hackaday article supports my thesis in the face of those who reject fundamental infosec principles.

Sounds like they have their shit together.

AMD abandons customers of their older products. AMD only reacted as they did because the defect was found in recent hardware. If you equate the similar mentality that also brings designed obolescence to “having their shit together”, you can only speak from the standpoint of a shareholder. When a serious 0-day emerges on a 10+ year old AMD spychip, it’s foolish to assume AMD will have their shit together and patch it. They will have their shit together only in terms of the corporate bottom line, not to the ethical extent of protecting /all/ their customers.

There are plenty examples of AMD not having their shit together, such as refusing to patch Spectre on some of their own products. Introducing the spychip in the first place is not “having their shit together” for the demographic of non-corporate consumers.

Create a post

Discussing ways to reduce waste and build community!

Celebrate thrift as a virtue, talk about creative ways to make do, or show off how you reused something!

  • 1 user online
  • 1 user / day
  • 8 users / week
  • 8 users / month
  • 67 users / 6 months
  • 1 subscriber
  • 127 Posts
  • 1.05K Comments
  • Modlog