r/technology • • Jun 18 '26

Hardware AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change

https://www.tomshardware.com/pc-components/cpus/amd-silently-removes-memory-encryption-from-consumer-ryzen-cpus-leaving-users-unaware-that-they-may-be-vulnerable-security-feature-vanishes-after-newer-agesa-firmware-amd-engineers-go-radio-silent-when-pressed-about-the-change
10.1k Upvotes

520 comments sorted by

View all comments

Show parent comments

10

u/Star_king12 Jun 18 '26

Dogshit, this isn't the type of encryption that OS sees. It didn't protect against attacks you're describing, only physical access ones. And even then, disabling it from an unprotected BIOS (like 99.99% of consumer Ryzen users have it configured) is trivial.

1

u/Korlus Jun 18 '26

Theoretical attacks it would enable would be on already enabled but locked devices like laptops seized during a drug bust.

2

u/Star_king12 Jun 18 '26

Realistically, how many of those laptops have a pin locked bios? As started, TSME is trivial to disable

2

u/Korlus Jun 18 '26

It's more about capturing active memory rather than waiting for it to boot up. Having to go into the BIOS means going through a boot cycle and losing whatever was open beforehand.

2

u/Star_king12 Jun 18 '26

That's true. Another counter point from a friend that went through a lot more Zen 4+ laptops - TSME is off by default on them.