cross-posted from: https://lemmy.sdf.org/post/58764195

I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.

So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.

It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.

  • evenwicht@lemmy.sdf.orgOP
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    23 days ago

    The evidence shows it takes a higher level of knowledge and more specialized knowledge to exploit the thing

    I see no evidence from you here. Yes, it requires a big brain. But it does not require a nation state as you originally claimed (which is a composition of many well-paid big brains dedicated to the work professionally). Cybercriminals are not limited to nation states. They operate in all scales, some organised, some not. The evidence shows that a bug in a driver for the spychip is all it takes:

    https://hackaday.com/2021/10/01/flaw-in-amd-platform-security-processor-affects-millions-of-computers/

    • Bane_Killgrind@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      23 days ago

      Man this is some fearmongering.

      Dude you are more likely to get viruses and exploited running the older hardware.

      I understand that vulnerabilities pop up, but at least the within a decade recent stuff gets patched.

      • evenwicht@lemmy.sdf.orgOP
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        23 days ago

        Man this is some fearmongering.

        The evidence is in front of you. Hackaday.com is publishing facts. These facts do not make you fearful yet you call them fearmongering.

        Dude you are more likely to get viruses and exploited running the older hardware.

        Nonsense. Vulns in the older hardware are mostly of the known variety. New hardware is rich in the unknown variety of vulns, which by their nature you don’t know about and cannot control for.

        I understand that vulnerabilities pop up, but at least the within a decade recent stuff gets patched.

        And new vulns get introduced. Even the patches themselves bring new vulns.

          • evenwicht@lemmy.sdf.orgOP
            link
            fedilink
            arrow-up
            1
            ·
            22 days ago

            “Fearmongering” was your response to the hackaday link – which supports my thesis not yours. Now you say it’s fine despite the contradiction with the narrative you try to peddle. You have some cognitive dissonance to sort out.

              • evenwicht@lemmy.sdf.orgOP
                link
                fedilink
                arrow-up
                1
                ·
                22 days ago

                Of course it does. It spotlights the PSP infosec shitshow arising out of the AMD spychips. Also shows that a single individual researcher was able to discover it and w/some collaborators demo the exploit (no nation state actor or nation state budgets needed). You have failed to understand my position at a basic level if you can’t see this.

                • Bane_Killgrind@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  22 days ago

                  AMD’s advice is to upgrade to the ADM PSP driver 5.17.0.0 through Windows Update, or to download AMD Chipset Driver 3.08.17.735. Presumably, this solves the issue by properly zeroing out memory during allocation, as well as freeing up memory properly when its no longer needed.

                  Overall, a software fix is enough to solve the issue, and its a vulnerability that lacks some of the scare factor of bigger finds like Meltdown and Spectre from years past.

                  Sounds like they have their shit together.

                  One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

                  • evenwicht@lemmy.sdf.orgOP
                    link
                    fedilink
                    arrow-up
                    1
                    ·
                    edit-2
                    22 days ago

                    One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

                    Of course. The wide-scale big picture thesis is that it’s foolish to needlessly add an attack surface to the core of your CPU. To those who are infosec aware already accept that automatically because it follows from basic prevailing well-established principles of the infosec discipline. We don’t need to wait for the attack surface to be exploited before realising that the attack surface exists. In laymans terms, we lock our doors even if we have never been intruded on.

                    The infosec uninformed don’t practice security by default. They favor the most convenient decision (to run the fastest chip) and will not consider security in the absence of a specific exploit. The hackaday article gives that. It does nothing to sway experts who already know it’s rock-stupid to needlessly introduce an attack surface. The hackaday article supports my thesis in the face of those who reject fundamental infosec principles.

                    Sounds like they have their shit together.

                    AMD abandons customers of their older products. AMD only reacted as they did because the defect was found in recent hardware. If you equate the similar mentality that also brings designed obolescence to “having their shit together”, you can only speak from the standpoint of a shareholder. When a serious 0-day emerges on a 10+ year old AMD spychip, it’s foolish to assume AMD will have their shit together and patch it. They will have their shit together only in terms of the corporate bottom line, not to the ethical extent of protecting /all/ their customers.

                    There are plenty examples of AMD not having their shit together, such as refusing to patch Spectre on some of their own products. Introducing the spychip in the first place is not “having their shit together” for the demographic of non-corporate consumers.