cross-posted from: https://lemmy.sdf.org/post/58764195

I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.

So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.

It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.

@evenwicht@lemmy.sdf.org
creator
link
fedilink
1
edit-2
4d

Of course it does. It spotlights the PSP infosec shitshow arising out of the AMD spychips. Also shows that a single individual researcher was able to discover it and w/some collaborators demo the exploit (no nation state actor or nation state budgets needed). You have failed to understand my position at a basic level if you can’t see this.

AMD’s advice is to upgrade to the ADM PSP driver 5.17.0.0 through Windows Update, or to download AMD Chipset Driver 3.08.17.735. Presumably, this solves the issue by properly zeroing out memory during allocation, as well as freeing up memory properly when its no longer needed.

Overall, a software fix is enough to solve the issue, and its a vulnerability that lacks some of the scare factor of bigger finds like Meltdown and Spectre from years past.

Sounds like they have their shit together.

One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

@evenwicht@lemmy.sdf.org
creator
link
fedilink
1
edit-2
4d

One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

Of course. The wide-scale big picture thesis is that it’s foolish to needlessly add an attack surface to the core of your CPU. To those who are infosec aware already accept that automatically because it follows from basic prevailing well-established principles of the infosec discipline. We don’t need to wait for the attack surface to be exploited before realising that the attack surface exists. In laymans terms, we lock our doors even if we have never been intruded on.

The infosec uninformed don’t practice security by default. They favor the most convenient decision (to run the fastest chip) and will not consider security in the absence of a specific exploit. The hackaday article gives that. It does nothing to sway experts who already know it’s rock-stupid to needlessly introduce an attack surface. The hackaday article supports my thesis in the face of those who reject fundamental infosec principles.

Sounds like they have their shit together.

AMD abandons customers of their older products. AMD only reacted as they did because the defect was found in recent hardware. If you equate the similar mentality that also brings designed obolescence to “having their shit together”, you can only speak from the standpoint of a shareholder. When a serious 0-day emerges on a 10+ year old AMD spychip, it’s foolish to assume AMD will have their shit together and patch it. They will have their shit together only in terms of the corporate bottom line, not to the ethical extent of protecting /all/ their customers.

There are plenty examples of AMD not having their shit together, such as refusing to patch Spectre on some of their own products. Introducing the spychip in the first place is not “having their shit together” for the demographic of non-corporate consumers.

Attack surface is reduced with architecture like this. You really don’t know what you are talking about or what problems are addressed with this stuff.

You still seem to think that other people’s resources are infinite, but this time criticising a corp that should have a duty of care in this regard. Bravo, you are on the right track. So where is the line drawn? Things that haven’t been manufactured since 2005? 2000? Please elucidate what the correct policy should be.

@evenwicht@lemmy.sdf.org
creator
link
fedilink
0
edit-2
2d

Attack surface is reduced with architecture like this. You really don’t know what you are talking about or what problems are addressed with this stuff.

Bullshit. You really have no clue what you are talking about. The absence of an attack surface is as small as an attack surface gets. When you add something that can be attacked, you are adding an attack surface that was not there before you added it.

You still seem to think that other people’s resources are infinite,

On the contrary, you are the one advocating for resource waste. Omitting the spychip uses far fewer resources both for producing and then customer resources for powering it. Then human resources are wasted for controlling the attacks (because you added an attack surface) and for accidental defects (because you added the unnecessary complexity of closed-source software which ensures there is more code that can go wrong and also simultaneously fewer brains reviewing it).

It’s not just an extra chip. That chip needs a driver. The driver doesn’t write itself. So that takes resources. And that driver creates another point of failure and attack surface. It also requires resources to maintain that driver. And when AMD disregards their “duty of care” because the chip is too old to be profitable thus drops support, the resources of consumers are wasted dealing with the problem (which they should never have had in the first place).

but this time criticising a corp that should have a duty of care in this regard.

You sound like a corporate spokesperson for a chip maker. “Duty of care” entails not subjecting your customer to a needless attack surface. What you fail to grasp is the spychip is for corporate customers, not individuals who do not need a closed-source blob in the core of their CPU. Individuals did not ask for a nanny. We requested a CPU that we control ourselves. Forcing us (individuals) to have a nanny we don’t want is a reckless abandonment of duty.

@Bane_Killgrind@lemmy.dbzer0.com
link
fedilink
English
1
edit-2
2d

The absence of an attack surface is as small as an attack surface gets.

Yes and the things that these chips process used to be processed on the main CPU, relying on software to prevent malicious access.

Now the attack surface, which used to be every implementation of every software, is reduced to the implementation of the world separation these chips provide.

You still aren’t talking about the technology, you are spouting “common sense” nonsense like new chips using single digit watts of power are less efficient than old chips using dozens of watts of power.

Garbage.

Edit: again, what is the cutoff? Should they still support procs from 1995? 1990?

@evenwicht@lemmy.sdf.org
creator
link
fedilink
0
edit-2
2d

Yes and the things that these chips process used to be processed on the main CPU, relying on software to prevent malicious access.

Rightfully so.

Correction to your utter pro-corporate drivel:

Now the attack surface, which used to be every implementation of every software, is reduced expanded to the unreachable closed-source implementation that makes consumers dependant on a corporate of the world separation with an imbalance of power these chips provide subject consumers to.

You still aren’t talking about the technology

The thread was originally about e-waste of technology. Your thread crap has discarded the e-waste discussion, so of course I am talking about technology. This thread branch is about avoiding undisclosed opaque technology with an attack surface we don’t need.

, you are spouting “common sense” nonsense like new chips using single digit watts of power are less efficient

The spouting of nonsense comes when you neglect to make a meaningful comparison that actually reveals the waste of the spychip. You can’t hide the spychip’s waste by choosing processors of different effeciencies from different time periods.

than old chips using dozens of watts of power.

You missed the link about new machines still using a 2013 pre-spychip because the TDP is 17w. But I guess it hardly matters when you’re trying to make a dishonest comparison anyway to conceal waste.

Edit: again, what is the cutoff? Should they still support procs from 1995? 1990?

If it’s a closed-source spychip, it should be supported for as long as the chip maker exists. And when they go under, they should be forced to disclose the source code. If they don’t like that, they should quit making the spychips. If they are ruined and sink because they failed to support their crippled support-needy garbage, then rightfully so.

If it’s not a spychip, it needs no support from the maker apart from documentation, which should always be available as long as the chip maker exists. And thereafter available on archive.org.

different time periods

Please point to modern processors or SoC available to consumers that does not have these subprocessors. Selling “new” 13 year old processors is fine, but that won’t last forever and technology needs change.

Again, you are spouting emotional, uninformed garbage. There is no technical definition of attack surface that would classify commingled processing as better than bifurcated processing.

I honestly believe that you are being paid to post this stuff to sabotage real beneficial collaboration.

@evenwicht@lemmy.sdf.org
creator
link
fedilink
0
edit-2
2d

Please point to modern processors or SoC available to consumers that does not have these subprocessors.

The IBM power 9 is one, but it’s red herring anyway because you’re still looking to weasel out of acknowledging that the only relevent comparison is the same chip with and without an spychip. Looking to other chips is nothing more than a futile attempt to hide the fact that spychip is not wasting energy. I doubt you will find an audience naive enough to buy your nonsense… but if you find them, sell them a bridge.

technology needs change.

Not this change.

Again, you are spouting emotional, uninformed garbage.

Again, your stance is driven by emotion as you continue to fail to justify your closed-source support-needy garbage.

There is no technical definition of attack surface that would classify commingled processing as better than bifurcated processing.

It doesn’t need to. An attack surface definition that attempts classification would be a broken definition by someone attempting shenanigans to hide their attack surface. Someone hoping to bullshit consumers who don’t want extra vulns and then being at the mercy of the corporate supplier’s will to fix.

I honestly believe that you are being paid to post this stuff to sabotage real beneficial collaboration.

You can test that theory by actually putting forward an effective logical argument that actually justifies your position. You can only blame yourself for failing to articulate a sensible idea.

Create a post

Discussing ways to reduce waste and build community!

Celebrate thrift as a virtue, talk about creative ways to make do, or show off how you reused something!

  • 1 user online
  • 1 user / day
  • 8 users / week
  • 8 users / month
  • 67 users / 6 months
  • 1 subscriber
  • 127 Posts
  • 1.05K Comments
  • Modlog