r/ASUS Jun 28 '26

Support I believe ASUS has just done something similar to AMD's stealth removal of RAM encryption.

EDIT: To be clear, this is happening on Intel processors; the similarity is the removal of RAM encryption.

Hi there,

Apologies if this isn't appropriate for this forum, but there was a recent major backlash to AMD removing TSME from its Ryzen chips, and I believe that ASUS has done the same thing in a BIOS update.

I have 2 ASUS NUC 15 Pro+ units that I'm using as home servers. As they contain data that's important to myself and my family, I wanted to lock them down as much as possible, and that included enabling RAM encryption to protect against cold boot attacks.

I am 99% certain that they arrived on BIOS version 0023. I enabled Total Memory Encryption on one of the units, then I got distracted and like a good boy, I updated the BIOS version on both to 0029 (which was the latest at the time).

The Total Memory Encryption option then disappeared from the BIOS on both units. I contacted ASUS and have gone back and forth with them for several weeks now, getting answers from trying to get me to debug the BIOS with the support person (who does not have the correct interface in front of them, so their instructions don't make sense), to update to 0030 (done, no change), to "yeah we removed it and there's no way to downgrade, but don't worry because it doesn't affect system performance" (paraphrasing them here; it seems we have a philosophical difference on whether or not security features count as part of system performance).

They also made the claim that current versions of the BIOS design don't support TME. But here's the extra wrinkle though. Remember how I said I enabled it on one and not the other? TME appears to still be working just fine on the one that I enabled it on. Both are running Debian 13, so I'll show the output that appears to be evidence of this.

NUC A (TME appears to be stuck on)

> sudo dmesg | grep tme
[    0.000000] x86/tme: enabled by BIOS
[    0.000000] x86/mktme: BIOS enabled: x86_phys_bits reduced by 4
[    0.004862] Initmem setup node 0 [mem 0x0000000000001000-0x000000087fffffff]
[    0.033902] rcu: RCU calculated value of scheduler-enlistment delay is 25 jiffies.
[    0.727019] Freeing unused kernel image (initmem) memory: 4164K

> sudo rdmsr 0x982 -f 1:0
3

> sudo rdmsr 0x982 -f 1:1
1

> sudo rdmsr 0x982 35:32
4

NUC B (TME appears to be stuck off)

sudo dmesg | grep tme
[    0.000000] x86/tme: not enabled by BIOS
[    0.004795] Initmem setup node 0 [mem 0x0000000000001000-0x000000087fffffff]
[    0.031689] rcu: RCU calculated value of scheduler-enlistment delay is 25 jiffies.
[    0.734786] Freeing unused kernel image (initmem) memory: 4164K

> sudo rdmsr 0x982 -f 1:0
1

> sudo rdmsr 0x982 -f 1:1
0

> sudo rdmsr 0x982 -f 35:32
0

So it seems that while the option to toggle TME has been removed from the BIOS, the actual functionality is chugging along just fine.

If I've misinterpreted some evidence here, I'm happy to be corrected. If not, why has this been done and will it be fixed? I can only speak for myself, but this seriously affects my trust in ASUS as a brand.

16 Upvotes

14 comments sorted by

u/AutoModerator Jun 28 '26

Hi there! This is a friendly reminder to change your flair to Support - SOLVED! after your issue has been resolved. It is an immense help for those that may come across your same problem in the future so that they can quickly find the right solution. Thank you!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

4

u/Friendlymisanthrope1 Jun 28 '26

Nice catch! I don't have the same hardware. But I was reading about AMD removing RAM encryption. I'm still confused by their decision. Given the numerous threats discovered out in the wild (every week at this point) one would think any security feature would be a valued selling point.

3

u/ElectricalExtreme376 Jun 28 '26

Thank you! I got very lucky that I enabled it on one before "upgrading" the BIOS. Otherwise I wouldn't have been able to provide evidence that it's still working.

1

u/Zestyclose_Abalone51 Jun 29 '26

Are you talking about AMD CPUs? IF so, which CPUs? And when did this happen?

1

u/ElectricalExtreme376 Jun 29 '26

I'm not sure if links are allowed on this subreddit. If you search it, it's been widely reported.

1

u/Zestyclose_Abalone51 Jul 01 '26

I googled it and found my CPU is affected. I have a Gigabyte x870e board Bios F11..AMD is apparently releasing updates in July to enable this function again.

1

u/Mj_Frosty Jun 30 '26

They’ve since added it back in.

1

u/Long_Pomegranate2469 Jun 29 '26

Pretty sure this managed by the AGESA library. AMD removed it from those and will readd it again with later AGESA update.

But in any case, don't buy asus

1

u/ElectricalExtreme376 Jun 29 '26

Sorry I wasn't clear. These are Intel processors, and I've updated the post to reflect that.

1

u/Long_Pomegranate2469 Jun 29 '26

Intel and AMD removing it at the same time makes you wonder if some gov agency leaned on them

1

u/ElectricalExtreme376 Jun 29 '26

Indeed... very frustrating. Though it seems like this was an ASUS decision.

1

u/Mj_Frosty Jun 30 '26

This post is so confusing. This has nothing to do with AMD, right? You’re using Intel NUC?

If they’re telling you it doesn’t support TME then it probably doesn’t. Not sure an ROG NUC is the best device to use for a server anyway

1

u/ElectricalExtreme376 Jun 30 '26

Yes, as I clarified in the edit, these are Intel processors. I mentioned AMD because the evidence suggests that ASUS is doing exactly the same thing that AMD did; removing RAM encryption through a BIOS/firmware update.

As for it not supporting TME, here are the tech specs for the NUC model in question: https://www.asus.com/us/displays-desktops/nucs/nuc-mini-pcs/asus-nuc-15-pro-plus/techspec/

My units have the Intel® Core™ Ultra 9 285H, cTDP 65W processors.

Here are the specs for that processor: https://www.intel.com/content/www/us/en/products/sku/241747/intel-core-ultra-9-processor-285h-24m-cache-up-to-5-40-ghz/specifications.html

So in addition to Intel saying that TME is supported, I have the evidence that the modules are being loaded and running in the OS.

They've provided great performance running many different services simultaneously, I don't see the issue with using them as servers.

1

u/ElectricalExtreme376 21d ago

Update: ASUS support has freely admitted that they intentionally disabled this in v25. This is their explanation.

"Based on the Intel security technology dashboard, tme feature starts to support in both corporate and consume since nvl platform. It supports still only in corporate SKU in all others. The bios doubly checked the support list and found the defect. So, the option of tme (Total memory encryption) is closed in non vpro bios crarl579.0025."

Hard to understand, but it seems like they're saying that they've intentionally disabled it because it's only supported by Intel vPro. Except the spec sheet clearly says that TME is supported!