3 ms·
I hate to be a Debbie Downer / conspiracy borderline, but nothing will change if all of this is true. Some apologies, "it's an oversight, we'll do better", "we
by Keyframe 9y ago
I hate to be a Debbie Downer / conspiracy borderline, but nothing will change if all of this is true. Some apologies, "it's an oversight, we'll do better", "we take security seriously"... and nada. Maybe some provisional solutions which seem good, but in the back - things will remain status quo.
- rwmj 9y agoThe upcoming SiFive RISC-V 64 bit chip has an open source management layer. In fact the management layer is open source already, before the chips are available generally: https://github.com/sifive/freedom-u-sdk/tree/new https://github.com/sifive/freedom-u-sdk/tree/new (under riscv-pk).
- Keyframe 9y agoRISC-V, in general, excites me very much!
- KGIII 9y agoFor a very brief moment in time, there was some hope that AMD would release their equivalent as open source. That hope was dashed and they will be doing no such thing. For the time being, ARM is making headway in creating usable chips for more serious computing. Well, I guess I should say designing, as opposed to making. I do have current gen hardware and some older hardware, should it reach the point where I need to be concerned. Though, at least theoretically, a good hardware firewall should prevent this from being exploited but most consumers aren't going to invest the effort and money to do so. I'm not really sure what this means for the future of personal computing. Like you say, nothing is going to change. They will continue to roll things like this out onto unexpecting users. I don't have a problem with this being included, but I do have a problem with it not being something you can disable. In fact, I'd prefer it to be off by default. I suppose it'd be okay to have it configured by the OEM, as some large orders may wish it in by default. Either way, it is insecure by design and they show no signs of changing that. It's rather disappointing. I have read, but not yet verified, that AMD's version can be turned off in the BIOS. That also assumes that off means actually off.
- pbhjpbhj 9y agoSounds like AMD know how to pressure the TLAs for a better deal.
- ece 9y agoIt seems like SVM turns on and off with the extensions KVM (AMD-V) uses in my gigabyte motherboard for a Ryzen 7. All the TPM related functions (including PSP/AMD SP) are another separate option called "AMD CPU fTPM", and are disabled by default. Business models based around certain kinds of binning (security instructions that are openly documented) and tying functions together (in case of a 3rd party chipset ever using the same chip) need to stop. 3rd party chipsets or desktop class arm/risc-v to break the x86 oligopoly at this point around security need to be developed.
- zizek23 9y agoAnd apologists assuring people there is nothing to get worried about, dismissing concern as conspiracy theory and demanding 'concrete' evidence of wrong doing. Given recent history skepticism must move to these individuals and their motives.