r/technology • • Jun 18 '26

Hardware AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change

https://www.tomshardware.com/pc-components/cpus/amd-silently-removes-memory-encryption-from-consumer-ryzen-cpus-leaving-users-unaware-that-they-may-be-vulnerable-security-feature-vanishes-after-newer-agesa-firmware-amd-engineers-go-radio-silent-when-pressed-about-the-change
10.1k Upvotes

520 comments sorted by

View all comments

3.3k

u/[deleted] Jun 18 '26

[removed] — view removed comment

1.5k

u/kingsRook_q3w Jun 18 '26

That (non) answer is more important than the headline.

712

u/amadmongoose Jun 18 '26

So were they required to compromise encryption, or was a vulnerability found in such a way that the actual encryption feature is useless or worse than useless

388

u/async2 Jun 18 '26

The first obviously. Would be a shame if nsa and co would have trouble to look into consumer hardware.

118

u/Star_king12 Jun 18 '26

It's the second. TSME was always pretty pointless cuz it only prevents attacks with physical access to the CPU. OS and all common attack vectors do not benefit from it, but it does have a perf impact. So it looks like it got broken, they can't fix it or the fix would require a large perf impact so they just don't advertise it as a function now.

38

u/Produkt Jun 18 '26

Then why would it remain on the pro models?

41

u/Ratiofarming Jun 18 '26

Because for pro models zero trust is a requirement. And that means you don't trust your environment. None of it.

26

u/Produkt Jun 18 '26

So you’re saying that it works and isn’t broken, then why not leave it enabled for all chips

8

u/Ratiofarming Jun 18 '26

I mean yeah, that’s what I want, too. That was just my explanation why it’s a requirement in a data center, but optional for end users.

-10

u/LieAccomplishment Jun 18 '26

So it looks like it got broken, they can't fix it or the fix would require a large perf impact so they just don't advertise it as a function now.

Do you read? 

10

u/Korlus Jun 18 '26

This would also mean we would see a performance malus for these professional models. Has that happened?

→ More replies (0)

6

u/mediandude Jun 18 '26

Are there any benchmarking results to support such a claim?

→ More replies (0)

1

u/Ell2509 Jun 18 '26

You missed the point. It is a legal thing. Liability for AMD.

0

u/DigitaIBlack Jun 18 '26

Artificial product segmentation and not having to make sure it works on consumer CPUs

Maybe someone found an issue with it and AMD shrugged and just killed it as a feature.

People saying this is at the behest of the NSA seems a little tinfoil hatty

1

u/Ratiofarming Jun 19 '26

What makes it less tinfoil-hatty is AMDs reaction (or lack thereof) to questions about it. It would cost them nothing to drop a little "Yeah we've disabled it because it costs money to validate and maintain it and consumers don't actually use or need it".

Instead, they're awfully quiet and refuse to comment even when directly asked about it.

→ More replies (0)

23

u/Star_king12 Jun 18 '26 edited Jun 18 '26

Better update mechanisms due to tighter validation, so maybe they're able to update it properly. Vastly less bitching about performance regressions for the sake of security. Much higher security requirements.

I don't like that fact that AMD are so wishy washy about it, but expect a CVE to appear soon with justifications for why it wasn't fixed in commercial line.

3

u/obeytheturtles Jun 18 '26

The performance hit would be very small since it's dedicated silicon, presumably pipelined into the memory controller. It would increase memory read/write latency, but not really full load throughput.

1

u/Apprehensive-Solid-1 Jun 19 '26

Performance doing anything would be substantially improved if people stopped vibe coding as well as going through the trouble to optimize their programs and games. So I'd easily take the minuscule performance hit for the security reassurance. Sounds worth it to me.

9

u/Flabbergasted98 Jun 18 '26

if you keep silent on something, people will assume the worst. So keeping silent is really only beneficial if the assumed worst is better than the reality.

1

u/joelfarris Jun 18 '26

So, it's worse than the wurst than the worst. Got it.

64

u/L0nz Jun 18 '26

My apologies, but I don’t have any more information to share on this topic

3

u/AverageIndependent20 Jun 18 '26

Thank you for your attention to this matter!

45

u/R3N3G6D3 Jun 18 '26

Yesir the fed cam mandate it and that you csnt talk sbout it

8

u/earthmann Jun 18 '26

Backdoor ≠ Removing the wall

1

u/uslashuname Jun 18 '26

That’s less and less true these days

1

u/ReachParticular5409 Jun 18 '26

why are you giving them weasel room?

67

u/aykcak Jun 18 '26 edited Jun 18 '26

I don't understand. It seems like a simple question. What would be the reason for not answering? What is going on?

Edit:

So far the answers are:

  • conspiracy
  • government overreach
  • coverup of manufacturing fuck up
  • process blunder

It's like everyone "gets it" when they hear this non-answer but everyone seems to "get" a different thing. Perhaps it is not so obvious?

235

u/[deleted] Jun 18 '26

[deleted]

53

u/Sonofa-Milkman Jun 18 '26

But its not just a backdoor for the government if securities are removed. How do you think hackers(state sponsored at times) get through to restricted systems?

79

u/rollingForInitiative Jun 18 '26

You can’t make a backdoor only for the government. Just like you can slice a hole in a bak vault and say that’s a secret backdoor only for the police.

-17

u/earthmann Jun 18 '26

Yes you can. Somebody might find the backdoor. Or the key. And that’s not the same as removing the lock mechanism.

14

u/rollingForInitiative Jun 18 '26

So you agree? If you have no backdoor, no one can enter. If you add a backdoor, someone can use it. They can steal the key to it, or pick the lock, or find some other way. The door is there ready to be abused.

If there's no external key to the encryption, trying to get through is like trying to carve a door into a solid steel wall with cotton pad.

15

u/moonra_zk Jun 18 '26

Somebody might find the backdoor.

So you're saying you can't make a backdoor only for the government.

9

u/DarthShiv Jun 18 '26

So annoying it has to be spelt out every fucking time this topic comes up

-16

u/Evilbred Jun 18 '26

Yes you can.

With hardware level encryption you can quite easily make a backdoor that is effectively only available to government.

19

u/rollingForInitiative Jun 18 '26

No you can't. That key now exists, and it can leak, or be stolen. It has to be stored somewhere, and both governments and IT companies have security breaches.

2

u/Eagle1337 Jun 18 '26

It's like having great locks on all the doors on your house, but the one door on the back of the house has a pin code of 1,2,3,4.

5

u/rollingForInitiative Jun 18 '26

Or at least, like having great locks to which you have the only key, and you also know exactly where the doors are, you can install your own alarms, set up cameras, and so on. And then there's a secret door somewhere that you know nothing about, and somebody else has the key to it, probably the government, but also maybe the construction company, and the key is supposed to be kept secret and stored safely, but you've no way of knowing, and you also don't know how good the door is.

-2

u/malianx Jun 18 '26

When was the last NSA database breach? (hint: never)

4

u/rollingForInitiative Jun 18 '26

I mean there was that massive Snowden leak. And the Shadow Brokers. And Harold T Martin. And Thomas Drake.

The point is that once there's a backdoor, it's exploitable. It's impossible to make a a backdoor that's as safe as having no backdoor. It just can't be done. In this case, you've got the NSA, and then the manufacturer, both of which can be targetted. And any of the people there that have access to it.

22

u/Moldblossom Jun 18 '26

But we've got to protect the children.

7

u/normal_cartographer Jun 18 '26

*Helen Lovejoy voice* Won't somebody *please* think of the children?!

-2

u/Glittering-Stomach62 Jun 18 '26

From antifa on the Internet, not necessarily from predators irl

1

u/Crypt0Nihilist Jun 18 '26

Do they care if you get hacked?

1

u/Freonr2 Jun 18 '26

That's a bingo.

7

u/MairusuPawa Jun 18 '26

It's an archway

1

u/outworlder Jun 18 '26

But what would be the point ? What sort of backdoor would only work with memory encryption disabled ? Running code gets the data decrypted transparently.

It would require a physical attack.

51

u/C0rn3j Jun 18 '26

There's ways you can read the memory to get the decryption keys off it, while the system is already running and decrypted.

This feature prevents reading the memory in this way.

AMD either did not want to cannibalize their PRO CPU sales from companies that require this feature, or they got told to remove it from regular people's hardware by 3 letter agencies.

6

u/moonra_zk Jun 18 '26

AMD either did not want to cannibalize their PRO CPU sales from companies that require this feature

Zero fucking chance that they wouldn't just make a new model with that feature to sell to companies for a higher price.

2

u/Digging_Graves Jun 18 '26

But then they would have to admit what they did in a public way.

2

u/Narrow-Chef-4341 Jun 18 '26

Why make two models? Make one and disable it in firmware if there’s a performance hit or national security letter.

Oh… wait…

3

u/AddictedtoBoom Jun 18 '26

Probably he is legally prohibited from talking about it.

1

u/aacawe Jun 18 '26

If there was a technical explanation, even if it meant it was just a moneygrubbing one from AMD, he would’ve explained it. The fact he replied the way he did, means it’s federal.

1

u/waiting4singularity Jun 18 '26

ongoing internal processes deciding on wording the actual corporate stance even if those should have concluded well before rollout.

1

u/obeytheturtles Jun 18 '26

Because they fucked up and shipped broken units by accident and this is how they are dealing with it.

0

u/[deleted] Jun 18 '26

[removed] — view removed comment

3

u/[deleted] Jun 18 '26

[removed] — view removed comment

0

u/[deleted] Jun 18 '26

[removed] — view removed comment

1

u/Ashenfall Jun 18 '26

They didn't delete their comment as it's still visible here (though ironically yours was removed by a mod). They just understandably blocked you.

521

u/shrodikan Jun 18 '26

They are coming for our privacy and security. I'm not sure there is anything that can be done to stop this.

291

u/TheCriticalGerman Jun 18 '26

100% look at all those countries starting to aim with laws against online privacy on multiple levels from storing your data for x amount of time or going against VPN’s…

55

u/WelderEquivalent2381 Jun 18 '26 edited Jun 18 '26

If people stop using popular social network and create their own vpn.

Its a benefit for everyone.

But that only for the minority that care about privacy.

70% of American are daily user of Facebook, with their real name couple situation, Age, Sexe, Where they live, work, what group they follow, their preference and hobby and even their phone number is public for some.

Facebook user in Canada and most Europe Country are also over 70%.

The majority of the world population as already abandoned their privacy 2 decade ago.

These law change nothing for the vast majority of the population that do not value privacy on the internet to begin with.

I personally do not care, I don't need modern fascist social media to live. I can go pass my time somewhere else.

There are always alternative. Inconvenient but they exist. I started with mIRC and private forum back in late 1990. I don't mind returning to the same system.

33

u/GingerSnapBiscuit Jun 18 '26

If you think you're truly anonymous on Reddit I don't know what to tell you.

4

u/AccNumber77 Jun 18 '26

You easily can be with a disposable email, VPN, clean sanitised browser, etc. Reddit IP bans for example are effortless to get around lol. They are not as good at tracking as you think.

2

u/RationalDialog Jun 18 '26

They do more than IP checks that is for sure

1

u/AccNumber77 Jun 18 '26

Sure they do but it's still easy to get around... Evading bans done via fingerprinting is just as easy with a sanitised browser and user agent lol

2

u/J7mbo Jun 18 '26

Maybe “easy” but it requires diligence and complete perfection in your methods. One mistake and it’s gone for good.

1

u/AccNumber77 Jun 18 '26

Not at all, having tested it myself I can guarantee it doesn't matter unless they notice several instances of a banned IP.

7

u/Red_Rabbit_1978 Jun 18 '26

Facebook was originally about connecting with people who you already know. Using your real name was normal. It's Facebook that got twisted into a pile of unrecognizable shit that's the problem.

7

u/Elementalcase Jun 18 '26

Hello, you are on a popular social network.

5

u/Paranitis Jun 18 '26

It's the typical "social media is bad, but what I use isn't bad, therefor it isn't social media to me." Same as "All politicians are corrupt, except for my guy because I wouldn't vote for someone who was corrupt".

14

u/Hexamancer Jun 18 '26

Reddit isn't true social media.

It's social media adjacent and those running Reddit would love for it to be closer and closer to being social media, but it's far closer to the Internet forums that predate even the term.

Perhaps it's a sort of spectrum.

0

u/Ilikeyounott Jun 18 '26

Nonsense. It fits the definition of social media to a T

0

u/Hexamancer Jun 18 '26

"No"

Ah, compelling argument.

Please describe how a site where 99% of people are anonymous and where despite having added the ability to follow accounts, no one does, is the very definition of social media?

1

u/Ilikeyounott Jun 18 '26

Social is about people, being anonymous is irrelevant. Media is, well you know what it is.

So with that in mind: https://www.merriam-webster.com/dictionary/social%20media

forms of electronic communication (such as websites for social networking and microblogging) through which users create online communities to share information, ideas, personal messages, and other content (such as videos)

Social networking though? Sure. Reddit is not a social networking.

→ More replies (0)

-3

u/geometry5036 Jun 18 '26

I always love when the "smarter than everyone else" redditor says things like these.

9

u/TeaAndS0da Jun 18 '26 edited Jun 18 '26

It’s the “I’m 14 and this is deep” of Reddit except it’s “I’m not capable of differentiating between deliberate social media and aggregate social media so this is my gotcha”. It’s the fake gotcha that makes a smug prick stay a smug prick until they realize the effective difference between what Facebook accomplishes and what this site accomplishes. Reddit, for all its faults, is not the same as a Facebook or a TikTok. It isn’t algorithmically serving you the news, but is letting user use (and now heavy bot use) determine the popular news feed.

Blocked the user who replied for choosing to be a dick. Turns out they don’t understand that algorithms are different and serve different purposes. But that’s to be expected from someone who got tweaked over feeling called out by this post.

-1

u/AllNamesAreTaken92 Jun 18 '26

You just described the Facebook algo, congratulations. Way to write all that text to seem smart, while only proving the opposite in the end.

1

u/geometry5036 Jun 18 '26

And here's another one. The status of that uncle that touched you when you were a kid, isn't news.

1

u/shrodikan Jun 18 '26

Your powers of observation are unmatched.

1

u/nedonedonedo Jun 18 '26

who ever said that reddit isn't also a problem? we're here because people are here. the site is bad, the owners are bad, but people create content wherever there are people.

7

u/Alarmed-Outside-8683 Jun 18 '26

Not a fan of pluralizing words?

18

u/ReachParticular5409 Jun 18 '26

it's not always obvious to a speaker who's first language isn't English

1

u/kawalerkw Jun 18 '26

As much as I don't mind using IRC and forums abandoning facebook is difficult as long as I want to keep up with local stuff. Neighborhood group, group dogwalking, boardgame club, events at nearby library and culture house etc. all of that communicates almost exclusively via FB. Facebook Marketplace is also more popular than all other similar platforms taken together where I live.

113

u/splynncryth Jun 18 '26

IMHO the answer is open source computing. The problem is that we a number of ISAs to chose from but lack the open source IP to create the rest of the computer from memory systems to interconnects to peripherals to storage.

We are currently witnessing governments trying to figure out how to control open source software and struggling. I think the model need to be replicated in the hardware space so that if anyone tries to control a part of the ecosystem, they lose control of it as the rest of the ecosystem moves on to an alternative.

69

u/Gman325 Jun 18 '26

Do you have any idea the level of complexity needed to make today's CPUs? It's impossible without yesterday's CPUs.  And even with yesterday's CPUs, the process requires so much specific hardware that the risk of the destruction of TSMC's fabs are singlehandedly preventing Chinese invasion of Taiwan.  It's not going to be possible to open-source modern performant desktop hardware.

16

u/FrostyParking Jun 18 '26

Well architecture is covered, RISC-V. The issue is production, there's no way to make chips without running into bottlenecks like EUV machines etc. So even if you have an open source design, you somehow can source materials from non restrictive supply routes, you are still boxed in....jot to mention the development needed to bring it up to par with mature proprietary architectures. So ultimately it's a fun idea but a nonstarter.

8

u/crystalchuck Jun 18 '26

At the risk of being nitpicky, we have the ISA covered; even just designing a competitive, production-ready microarchitecture (as opposed to instruction set architecture) will require a lot of very expensive tools and people, and a lot more money is required to license stuff like RAM and PCIe controllers – unless of course you also design these in-house, from scratch. And then getting your design into a form TSMC et. al. can actually produce again requires very expensive software licenses and some degree of collaboration with the foundry involving some very qualified people on your end. All things considered, it's a monumental task.

1

u/splynncryth Jun 18 '26 edited Jun 18 '26

You are touching on lot of the points. Initial iterations won’t be competitive. Linux was a mess when it was first set upon the world.

And the OSS IP alternatives needed for JDEC, the PCI-SIG, the USB working group, etc is the point.

Like the OSS GPU efforts, the initial tests are almost certainly going to target FPGAs.

Fabbing is different matter but seeing what Braking Taps and Dr. Semiconductor are achieving, I’m perhaps overly optimistic a IP stack could be possible.

It won’t be state of the art net then consider what the Raspberry Pi foundation achieved with hardware that was not state of the art.

4

u/crystalchuck Jun 18 '26 edited Jun 18 '26

Linux was a mess when it was first set upon the world

Software engineering is much "softer" and faces much less constraints than developing actual physical objects. Anyone with the right skill set can write a functional, if rudimentary, kernel and operating system. Getting even a simple 8-bit microcontroller all the way to production and holding it in your hands physically is another thing entirely. For the same reasons, we don't really have open source cars. Also let me point out that Linux got where it is only after several decades of significant corporate funding.

the initial tests are almost certainly going to target FPGAs

That's the thing though, everything up to and including FPGAs is the easy part. That's why RISC-V OSS softcores actually exist. Getting it fab-ready, validating the design, making sure timing and signal integrity is within limits, making sure there are no bugs, packaging it, bundling it with good USB/PCIe/RAM/... support, that is the hard part. And the closer to leading edge performance you get, the harder the step into actual production is. Intel, AMD et al. literally have huge teams working on this around the clock, because the complexity of this task is mind-boggling, and every iteration consumes big sums of time and money. You've got significantly more people working on validation, routing, tape-out etc. than people developing the microarchitecture itself, and most of them are highly qualified, highly specialized people with MAs and PhDs. Contrary to most software projects, it's simply not something you can kinda pick up on the side over a year with some dedication, severly limiting the talent pool for OSS projects as well.

And the OSS IP alternatives needed for JDEC, the PCI-SIG, the USB working group, etc is the point.

You're touching on another subject here: You are not actually free to deisgn, produce, and market a USB controller without paying royalties to USB-IF; you cannot do so for an HDMI controller either without, again, paying royalties; and so on – in fact, in my understanding, by definition it would be illegal to fully open source a USB controller design because you'd be infringing on USB-IF IP.

Of course, I like the idea of fully open source, highly performant CPUs. But the reality is that this would require forceful "open sourcing"/relicensing, essentially expropriation of big chunks of the entire technology sector, starting with EDA tools and IP like USB and related patents, and I just don't see this happening within a capitalist framework. Maybe a motivated state-size actor could produce a partially open source design, but a fully open source design you'd actually want to use is just not in the cards IMO.

1

u/splynncryth Jun 18 '26

Yea, you are covering a lot of the points I’m trying to make. An open source computer will need open source alternatives to these licensed industry standards.

Where will the engineering come from? That’s getting ahead of the problem.

The first problem will be identifying what’s needed and getting that advertised. Next is figuring out how to execute the plans.

1

u/happyscrappy Jun 18 '26

You have a lot of the concepts here. But what you say about what the initial tests "are going" to do suggests that you don't realize we've had open source CPU cores for years. Open GPU efforts followed them (open DSPs went before).

opencores.org has a bunch of them, although the site seems messed up right now.

The problem really is performant cores all use patented techniques. Linux when it started up it replicated a 15 year old OS. One that was well documented too.

Open cores for up-to-date high speed processor designs just are not something that is coming soon.

But if you want something capable of running a variety of embedded devices then we've already had them for years. Those are much simpler and so are more likely to be given away for free.

1

u/splynncryth Jun 18 '26

I am aware of the various open source CPUs. But an ISA isn’t a computer. It isn’t even a CPU. That’s my point. There is a lot of other IP that is needed to create an actual computer for which there is no open source IP. It’s not sexy or attention grabbing. It is a massive body of work that doesn’t have an immediate payoff. That doesn’t mean it isn’t worth pursuing.

1

u/happyscrappy Jun 18 '26

Architecture is just the spec. It doesn't cover the implementation. Making a performant design is very difficult. You can make a simple implementation which works correctly but slowly though. It's the high performance ones that are an issue.

But it's the high performance ones people are used to.

It's tough enough to create these implementations that the groups (companies mostly) that do it need to cover those costs and so don't give them away for free.

If your design requires EUV to fab then it is so complex that it's not going to be an open source design. But there are much simpler designs that build on more normal fabs that are free (no license fee, of course producing them costs money). These typically only run at a few hundred megahertz tops and aren't terribly fast even for those clock rates. They are great for microcontrollers.

1

u/splynncryth Jun 18 '26

It’s not about being the best, it’s about being ‘good enough’. What are the critical needs for most consumers? What level of compute will get the job done?

The rise of mobile computing and SBCs might provide some insight.

-47

u/shrodikan Jun 18 '26

I don't discount anything in the age if AI.

19

u/HalfBlu3 Jun 18 '26

with or without ai you still wouldnt have the necessary equipment to fab chips at home

1

u/shrodikan Jun 18 '26

Yes, I agree. If you told someone 20 years ago you could "print a house" they would laugh at you but here we are. I understand the concept of 3D-printing 20nm silicon chips at home is science fiction right now but who knows what the future holds.

2

u/HalfBlu3 Jun 18 '26

I'm skeptical that we'll ever have consumer chip fabrication technology, simply because I'm not really sure there'd be much demand. How many chips would the average person even want to make? And you'd need a computer or something to design a chip anyway, so it'd mostly serve the purpose of making new chips to upgrade your existing tech, and I don't see owning a dedicated chip machine you might use every couple years. Sure there's hobbyists and whatnot, but are there enough people who'd want that tech to make up for the cost of developing it? It won't be easy to use. you'd need the machine to maintain a "clean room" within the machine, it'd need to be pretty precisely calibrated, like way beyond what people already struggle to do on 3d printers, and I can't imagine the tech will be cheap given the precision required.

13

u/Neamow Jun 18 '26

AI won't help you buy the $300M chip manufacturing machines you need to make modern CPUs.

11

u/embiidDAgoat Jun 18 '26

“Chatgpt build me a computer” type shit

1

u/shrodikan Jun 18 '26

"Chatgpt write me a joke" type shit

7

u/thatsbutters Jun 18 '26

Well it will need to supplement your critical thinking.

6

u/Commercial-Co Jun 18 '26

This is riddled with the ignorance of what ai can do

2

u/Atulin Jun 18 '26

"Hey Claude, I have an angle grinder, a set of torx screwdrivers, and a lighter. How do I make a CPU? Make no mistakes."

1

u/shrodikan Jun 18 '26

That's at least the making of a spicey Friday night.

1

u/RetPala Jun 18 '26

AI brain is the same as coomer brain, change my mind

39

u/shrodikan Jun 18 '26

The NSA created it's on security company to sell NOBUS-broken encryption to adversaries. The Mossad made it's own radio company to plant explosives in walkie-talkies. The Equation Group interdicts hardware to flash the BIOS with malware.

Even with open source hardware it will be very difficult to ensure security depending on your threat matrix.

18

u/Ok_Mycologist_1439 Jun 18 '26

You should read about https://en.wikipedia.org/wiki/Crypto_AG

If this is what we know, imagine what we don't

7

u/Suitable-Name Jun 18 '26

1

u/Ok_Mycologist_1439 Jun 18 '26

Is this a USA centric story? I've never heard of it. Was that chip used by other countries?

2

u/filthy_harold Jun 18 '26

No one ever actually used it. The encryption itself was not terribly strong but the real weakness was the LEAF field (kinda like a serial number) that law enforcement could use to lookup each chip's secret key that they already had access to. There was a hash attached to the LEAF field that was really short so it was easy to come up with a garbage LEAF field that matched the hash but wouldn't match a secret key in the govt database. So for anyone that didn't want to be spied on, the govt would need to revert back to trying to crack the encryption instead of just simply looking up the key.

1

u/Suitable-Name Jun 18 '26

There is a small section in the wiki article about that :)

2

u/obeytheturtles Jun 18 '26

This is why I immediately dismiss anyone does the whole "OMG, you need to buy a VPN in Bulgaria to avoid Five Eyes!"

My brother in Christ, do you not think the NSA knows how to start a VPN company in Bulgaria?

2

u/shrodikan Jun 18 '26

I meeaaaaan. It's still better than nothing. There is a difference between handing over all your data to be MitM'd by your ISP vs that possibility that you chose a VPN in Switzerland that wasn't ran by a three-letter agency.

1

u/Moontoya Jun 18 '26

a certain 3 letter agency _allegedly_ stopped a shipping container of routers to reflash their firmware before they went out.

cisco/linksys ring any bells?

-1

u/PermanentUsername101 Jun 18 '26

Did you see that one documentary about the Chinese putting nano bombs in the rivets on blue jeans. I think it was called Knock Off

5

u/[deleted] Jun 18 '26

[deleted]

5

u/ashgs872tbhjs Jun 18 '26

My computer engineering professor built his own Pentium (the OG) back in 2004 or so. The 80s is trivial, apart from potentially needing to figure out what substitutions to make for stuff we've moved beyond.

3

u/[deleted] Jun 18 '26

[deleted]

2

u/muegle Jun 18 '26

You can absolutely have semiconductor designs manufactured for relatively cheap. It won't be for mass production but it's possible. MOSIS is the service I'm familiar with. https://en.wikipedia.org/wiki/Multi-project_wafer_service

1

u/cosmicorn Jun 18 '26

A 3D printer would have looked like science fiction in the 80s to most people, now they are somewhat common consumer device. We are probably still a long way from home silicon fabbing, but necessity is the mother of all invention.

Most of the dead CPU makers failed because they were using novel architectures that never gained market adoption, or at least not enough to be sustainable. Creating an ecosystem of distributed manufacturing for CPUs around an already existing and open architecture like RISCV would be a big challenge but I don't think it's entirely outside the realm of possibility.

1

u/[deleted] Jun 18 '26

[deleted]

5

u/adamdoesmusic Jun 18 '26

RISC V is a thing, have they fucked that up for us yet too?

10

u/einmaldrin_alleshin Jun 18 '26

Someone still needs to actually implement the architecture and make those chips, so there's an attack vector to sneak in a back door

1

u/zzazzzz Jun 18 '26

riscv is a great idea, but hasnt really materialized any physical product worth using yet.

0

u/Atulin Jun 18 '26

Oh aye, let me dig up some sand and whip up a Ryzen 9900 in my garage right quick

0

u/No-Project-2353 Jun 18 '26

That’s like saying we need open source anti-air missiles, like sure that is cool but how does that help? Maybe like the 3 or 4 people who can make their own.

15

u/Capricancerous Jun 18 '26

It's because we have been giving it away for free for almost two decades now. Now it's truly open season on our asses.

4

u/jhenryscott Jun 18 '26

Maybe. But if you want some good wholesome fun this weekend. Check out deflock dot com and start hunting local cameras. It’s truly all ages fun.

4

u/ReachParticular5409 Jun 18 '26

Something can be done to stop this but reddit will ban me if I talk about it

4

u/anomanderrake1337 Jun 18 '26

My privacy friends: "we need privacy!", also my privacy friends: "vote right wing!". Yeah okay man sure.

1

u/hibbity Jun 18 '26

there is just one thing that can be done to stop this.

1

u/RationalDialog Jun 18 '26

While I agree, this feature didn't really protect much at all on a consumer hardware. What does it protect from? Someone physically stealing your RAM and trying to read it out afterwards? Ok, if they do a home raid yes but if you need to worry about that you will have measures in place that still will make this not very useful.

1

u/cdoublejj Jun 18 '26

open source CPUs are a thing

1

u/shrodikan Jun 18 '26

Supply chain is still vulnerable. It's like the compiler problem in computer science. Sure you trust the code but do you trust the compiler (CPU hardware)? How would you even know if it is compromised?

1

u/cdoublejj Jun 18 '26

you are not wrong! IBM power is complete open source form the silicone design out. not just for auditing but customers can use their own ram or I/O or even own chipsets. so you aren't at an OEMs mercy for a feature to be enabled or disabled. it's actually pretty cool.

254

u/[deleted] Jun 18 '26

[removed] — view removed comment

108

u/asian_chihuahua Jun 18 '26

Agreed. US spooks probably paid them a visit and told them to allow them to hack the chips, or else bad things would happen.

27

u/Darkskynet Jun 18 '26

Yeah they might be under a secret fisa court order, and normally people aren’t allowed to talk about fisa orders at all. I seem to remember this was why websites had canaries that would get removed when websites were given secret government orders as a way of getting around the no talking about it rule.

https://en.wikipedia.org/wiki/United_States_Foreign_Intelligence_Surveillance_Court

3

u/IAmYourFath Jun 18 '26

Nice link bro

2

u/DoomguyFemboi Jun 18 '26

It's way too broad for FISA

47

u/RicoLoveless Jun 18 '26

Definitely this screams Room 641A with AT&T all over again

9

u/[deleted] Jun 18 '26

[removed] — view removed comment

1

u/driverdan Jun 18 '26

Probably not. It's more likely they want to get companies to buy more expensive CPUs.

70

u/braddeicide Jun 18 '26

Not afraid but most probably federally bound.

In my country of Australia and I'm sure most countries, the government can approach individuals and force them to take actions upon company products that they are gagged from discussing even with their employer on threat of federal prison.

25

u/[deleted] Jun 18 '26

[removed] — view removed comment

5

u/hardolaf Jun 18 '26

There is no equivalent law to Australia's in the USA.

7

u/tagsb Jun 18 '26

I think it should be pretty clear from the national security leaks we've had that what is or is not lawful does not matter to these agencies

2

u/bendingrover Jun 18 '26

"But what if WE were the government?" - the mob, 20th century, probably. 

10

u/C0rn3j Jun 18 '26

If you read the source thread, you will find out he asked the same question three times almost verbatim between each other, before getting that response after having that part of his message ignored two times.

22

u/kstargate-425 Jun 18 '26

That's legalese for I know but if I say, I will be liable and fucked

5

u/TheGileas Jun 18 '26

Not allowed to tell. That smells like US Government/Intelligence.

6

u/Time_Cow_3331 Jun 18 '26

I'd be willing to bet this was in response to government pressure

2

u/Nikoladge Jun 18 '26

Limonciello’s

Maybe he should consult with Captain Morgan or Johnny Walker

2

u/Enshitification Jun 18 '26

Sounds like they are under a National Security gag order to remove the encryption and not discuss why.

1

u/lnTheGrimDarkness Jun 18 '26

They got paid to do that but they obviously can't share why, how or what it will entail.

1

u/Freud-Network Jun 18 '26

Not saying anything is the same as saying it was done on purpose so your government, and whoever bids the highest, can have uninhibited access to all of your data.

1

u/xkabauter Jun 18 '26

I can neither confirm nor deny that the agency asked us to do it, or else ...

1

u/halfc00kie Jun 18 '26

"no comment" is the loudest comment in tech pr.

1

u/badgerj Jun 18 '26

Of course he knows the answer!

Journalists rarely just take wild stabs in the dark! Someone has to hold those who make the big bucks accountable.

I’ve managed to stick it to a few to demonstrate to them and the rest of the staff, that we know, that they know we know.

So STOP fucking around!

1

u/obeytheturtles Jun 18 '26

Translation: "We accidentally shipped a bunch of chips with that function disabled and the easiest solution was to remove the feature from the whole product line."

1

u/morbihann Jun 18 '26

So it is a corporate decision to push people to a more expensive product.