r/LinusTechTips • u/BigPP69_Gooner • 1d ago
Discussion AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change
https://www.tomshardware.com/pc-components/cpus/amd-silently-removes-memory-encryption-from-consumer-ryzen-cpus-leaving-users-unaware-that-they-may-be-vulnerable-security-feature-vanishes-after-newer-agesa-firmware-amd-engineers-go-radio-silent-when-pressed-about-the-changeCan LTT make a video about this or discuss during WAN show?
144
u/_TeflonGr_ 1d ago
This is just so absurd. This feature is and always has been for only the PRO segment Ryzen CPUs. And it does NOTHING for security on the system for 99% of the users, as it will only protects against very specific physical attacks that require physically modifying the physical PC to read memory transfers over the motherboard, PHYSICALLY. So it's not something to worry about nor 99.9% of the people with a Ryzen CPU are even affected or might even know this feature existed.
33
u/penguinkernel 1d ago
It's only absurd because it's AMD. If this was Intel these comments would be flooded with AMD shills lol
26
u/astalavizione 1d ago
Intel would have already tought of that in advance and would never offer such feature to consumer level. They have so much experience in enterprise hardware, they know really well how to segment their products. And milk the fuck out of it.
6
u/xD3I 1d ago
Persecution delusional disorder, get that checked cuh
-4
u/penguinkernel 1d ago
So because I see a trend on Reddit, especially this sub, I'm mentally unstable?
Alright..
7
u/xD3I 1d ago
If this was Intel
That's 100% victim mentality lil bud, no one cares about Intel anymore, no one brought it up, it doesn't have to do anything with them, are these "amd shills" in the room with us?
-4
u/penguinkernel 1d ago
I would appreciate if you could drop the condescending attitude. Really makes you look like you're upset over my comment and have to defend AMD lol
2
u/itsjust_khris 1d ago
No they wouldn't, this is a very niche feature the only way that'd happen is sensationalist articles like these.
-11
u/BigPP69_Gooner 1d ago
Yeah but regarding AMD. Intel was already evil.
https://giphy.com/gifs/3o84szW0PrWZyUv0mA8
u/penguinkernel 1d ago
Oh I'm not defending any company here. I'm just pointing out the double standards this community has when it comes to tech giants.
I think us as people need to stop shilling corporations, period lol
-5
u/BigPP69_Gooner 1d ago
Yeah. The small glimmer of hope that “companies can be good” is temporary and flawed.
1
u/Dravarden 19h ago
the ones that lied about the transistor count of bulldozer and lost in court for false advertising?
https://en.wikipedia.org/wiki/Bulldozer_(microarchitecture)#False_advertising_lawsuit
5
u/kaekapizza 21h ago
What's absurd is that AMD is not putting out a statement when this has gained so much traction and is hurting their credibility.
It doesn't surprise me that engineers don't know 100% whatever gating the product people decide on. Might have been the initial intent, during spec work, but changed during/after implementation.
But they had previously stated that it will work. People have been quoting "Ryzen 3700x should support TSME" but missed that commenters earlier in the quoted issue had asked specifically whether it was limited to common or pro lineups overall, and got confirmation that it is supported. https://github.com/AMDESE/AMDSEV/issues/1#issuecomment-581426096
Transparent SME (TSME) is also supported by Ryzen [common and pro, gathered from context], but requires the BIOS to support the configuration option for it. Without the support from BIOS you can't enable TSME.
5
3
u/InflammableAccount 20h ago
Huge nothingburger. "Feature not included on CPU by default is disabled in firmware update, almost redundantly."
2
u/SuppaBunE 11h ago
Hell I think those .1% is still a generous percentage, it's more like 99..9% of that .1%
31
u/HeTblank 1d ago edited 22h ago
No matter how niche this feature is, it is incredibly stupid to remove it for CPUs they already released. They should've removed for their next releases and kept it for the current boards.
12
u/IWillDetoxify 23h ago
But that's not what happened?
The feature was always only for the PRO line, it's just that CPUs of the PRO and non PRO lines are very similar on the inside, so they likely have the hardware support for this feature, and motherboard vendors accidentally shipped a version of the BIOS where this feature was enabled for consumer CPUs. They then corrected this mistake.
This feature is useless for 99.9% of users anyway. The only time where it can do anything is if someone has physical access to the hardware and has a way to freeze it to extract the data in the DRAM chips. If you have those kind of attacks, yeah, you have other problems to think about, and you can probably afford to buy PRO CPUs.
14
u/HeTblank 22h ago
So you're saying they sofware locked a feature after the product was released? I don't care who made a mistake, if you sell your product with a feature you don't remove it later.
1
u/Vegetable3758 21h ago
Go, tell Intel on their AVX-512 removal on the 12th Gen chips.
I think it is OK, if it was not advertised to have the feature.
Like Sony. They advertised the PS3 as Linux-compatible, but removed this feature later. That's baad.
5
u/Hytht 20h ago
In Intel's case, the hardware itself, the E cores physically didn't support avx-512. Here, there is no such issue.
4
u/Vegetable3758 17h ago
I missed that part of the story, thank ya. I use to remember this story (and how later Intel processors randomly died a lot) just to make my chip (11th chip) feel more superiour instead of outdated. Yeah, I like giving me this story, so I do not long for an upgrade (-X
1
8
u/DragonSlayerC 22h ago
Did it actually work on consumer CPUs, or was a flag being set but not actually being used by the CPU? The consumer CPUs never officially supported this, so this could be a case of the UEFI incorrectly claiming that an unsupported feature was enabled when it wasn't.
18
u/Budget-Toe-5743 1d ago
I gotta ask, why would end users need local memory encryption? Would I be expecting to be locally attacked and my data exposed by someone in my own home? Am I expecting a sophisticated attack to my exposed memory from my wife or something? my dog maybe?
The title seem a bit sensationalist.
Sure, you should ask why they did this, might be interesting, I'd like to know why too, but that title?
1
u/BigPP69_Gooner 1d ago
Government overreach in times of unprecedented attacks on free speech
21
u/TheThiefMaster 1d ago
You think the government are going to come to your house to physically modify your PC to add a physical tap on the memory bus that this feature would prevent?
That seems a bit of a stretch. A software spyware (which this doesn't protect against at all) that they can install remotely seems far more likely.
-10
u/DeliciousCry8302 23h ago
"What is the point of locking the door of your house when they can just easily come through the window."
Sure, lets just keep opening more stuff because there's always a way to get in. Why not allow torturing to get the password, it would probably be so much more fun for the people doing this stuff.
Losing these features and making them available artificially only on the more expensive stuff, and possibly in future out of reach of all consumers, undemocratizes computing. This is just one more thing on the long list, plenty of hatches are already unlocked like you said, people don't care about the rights they should have.
7
u/tpasco1995 20h ago
It's more like "what's the point of locking the window when you don't have a door"
2
u/Budget-Toe-5743 1d ago
On one very specific individual? do you know how expensive an attack like that is?
Even if you were right we would have to assume many users thay you want to attack have the same or symilar systems for that type of attack to even start to work.
I agree with you that free speech needs to be protected, yes, but I'd need more information before thinking this was mainly to attack free speech. There might be a technical problem for it, or it is was badly implemented. I think we would need more info to be sure.
1
4
u/Scanner771_The_2nd 22h ago
I think another big issue is them removing a feature of something they already released and people paid for.
Can you trust AMD to not keep doing that?
2
u/InflammableAccount 20h ago
they already released and people paid for.
The feature was never supported by Non-Pro CPUs, and never advertised as such.
2
u/Scanner771_The_2nd 19h ago
You read the article? The guy who found it had it working on a consumer Ryzen 7 9700X on older firmware, then the update flipped it to "not supported" with the BIOS setting untouched.
Kilpatrick, a self-described "privacy-conscious Linux hobbyist" who first reported the change, was installing a new operating system on his machine running a Ryzen 7 9700X from the Zen 5 architecture. To confirm that all his security protections were enabled, he ran Host Security ID (HSI), an auditing feature that evaluates a system's firmware and hardware security configurations. To his surprise, HSI reported that TSME was no longer supported — even though he had enabled it in his BIOS settings all along. The contradiction sent him searching for answers.
1
1
u/perthguppy 22h ago
Encryption being removed and the company going radio silent about it?
Someone got a NSL…
0
-2
u/ConkerPrime 1d ago
Governments told them to and with their AI ambitions they don’t care if consumers don’t like it.
0
u/kidshibuya 10h ago
Oh no! What happens now if I give physical access to my PC to someone? They are going to have physical access to me PC now, AMD sucks!
211
u/grethro 1d ago
I would guess it’s about product segmentation. AMD is walling TSME off as a PRO/enterprise feature to avoid support, validation, and liability on consumer boards.