3 ms·
> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If
by theandrewbailey 4mo ago
> TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device.
If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Most desktops aren't locked inside a datacenter. Memory encryption is a valuable desktop (and laptop) security feature.
- CivBase 4mo agoYou'd need physical access while it is running as the target is using it.
- hnuser123456 4mo agoWhen the threat model is physical security, henchmen are also a consideration.
- transcriptase 4mo agoYeah if you’re worried about someone getting physical access to your PC for information you should probably be more worried about someone beating that information out of you first.
- WillPostForFood 4mo agoSo my PC runs 5% slower because someone could break into my house to get physical access to decrypt memory? OK sure, but not my top concern, and a bad tradeoff for the lost performance. And not only fair, but completely accurate to describe TSME as non-critical for *most* consumer desktops. I'd go as far as to say useless and counter-productive for most, but not all, consumer desktops.
- eYrKEC2 4mo agoDoes it run slower? I'd expect dedicated hardware to do that encryption/decryption, in which case there should be no difference.
- pseudohadamard 4mo agoI think it's more a reference to Spectre and Meltdown and Rowhammer and a bazillion other hold-my-beer attacks that have never, ever been used in the wild but that everyone pays the price for by having their CPUs slowed down by the countermeasures. Applying Unicorn Repellant is fine when there's no cost, but it definitely has a cost in these cases.
- Itoldmyselfso 4mo agoHow can you be so sure they have never been used in the wild? Surely not all uses of them get reported...
- pseudohadamard 4mo agoThe same way I'm fairly sure that no-one's ever been attacked by a unicorn. There could be lots of unreported attacks, but I'm pretty sure there aren't any actual ones. What we do have is millions of actual, real-world attacks (see any security body's top-ten list) that we aren't mitigating because we're too busy focusing on silly attacks that no-one ever uses.
- WillPostForFood 4mo agoI had read there was a ~5% slowdown with it enabled.
- deleted 4mo ago[deleted]
- futuraperdita 4mo agoSo you turn it off by default in BIOS and allow those that feel it's useful to them to enable it, and you solve for both sides of the problem.
- avadodin 4mo agoIf it's not your top concern, you're probably a government employee with full security clearance and the "consumer desktop" doubles as a pirated game rig, top secret NAS and Twitter battle box.
- halJordan 4mo agoThe 180 is incredible to see though. I remember when enforcing FDE was all the rage bc well, shit gets stolen. This stuff was a critical concern then. Apple got raked over the coals for months because they did nothing to prevent shoulder surfing (as if a phone could).
- rr808 4mo agoThe last few companies have all had desktops in datacenters with the local PC just a virtual terminal.
- cwillu 4mo agoIf the bad guys have physical access to my consumer desktop, I'm already well and truly fucked.
- cma 4mo ago> as it protects against attacks where the attacker needs physical access to the device. Doesn't it also protect against rowhammer-like attacks?
- anticensor 4mo agoIt converts some of silent bitflip errors into loud crashes, which is desirable in some use cases.