Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > After some more back-and-forth, Kilpatrick asked bluntly whether the flag being set to FALSE on consumer chips was a silicon-level limitation or a firmware policy decision — since one is permanent and the other is potentially reversible. Limonciello’s reply effectively closed the chapter. “My apologies, but I don’t have any more information to share on this topic,” he wrote.

    Too many people downplaying this as a simple business decision from AMDs side but the response here is what really makes this a story.

    Where there's smoke, there's fire.

  • For anyone getting late to the thread, they're reinstating TSME. They shouldn't have had to reinstate it to begin with, but it's good to see the pressure campaign worked.

    https://arstechnica.com/security/2026/06/following-user-outc...

    by hd4
  • I would be fine with this if it meant CPUs became slightly cheaper, but we know that's not going to happen.

    And there's been talk that now the so-called "AI companies" will start using more CPUs as well, due to "personal agentic agents", so I hope that people won't be priced out of CPUs too...

  • To be honest it never worked great - many issues (mostly freezes) with VFIO, NVidia drivers, amdgpu...
  • This sort of shenanigan is why it’s important to have a competitive market for CPUs.
  • I think we are in the era we have so many CPU choices.
  • it's exactly why we're not allowed a competitive market for CPUs

    we could all be burning our own tiny ~300nm feature size ICs at home for around the price of a blu ray burner and a dark room setup. Our silicon limitations are not for a lack of hardware, but rather a lack of freedom.

  • If my memory serves me correctly, this feature was never marketed by AMD for these CPUs and was unstable.

    The only mistake AMD potentially made here is not being transparent why it was disabled.

  • If it can be silently removed was it a security feature?

    Whilst I hate companies paying engineers to make things worse just to segment their market; I am not really seeing this as an important feature outside the data-center? If an evil-maid has hardware access they hack the USB and/or PCI not the RAM surely?

    by ZiiS
  • Removing it required AMD's firmware code signing keys. If an attacker has those and some time they can do much worse.
  • Sneakily and silently removing a feature in a firmware revision is not acceptable, security or otherwise.
  • I don't know how this works but does this mean if someone gained physical access to your locked running computer, they could gain access to your full encrypted drive and anything saved on disk?

    My reasoning there is if you used an encrypted drive, the decryption key you type when booting up would be stored in memory for the duration of that boot.

    This seems alarming because it means if someone broke into your living quarters they can bypass all forms of disk encryption if your machine was on and locked. Encrypting your disks seems like a reasonable thing to want to do with consumer grade hardware.

  • This feature was off by default in all the mobos I've seen.

    It causes many stability issues, as to my experience.

    The attack is sophisticated, Mr.Nobody, generally, should not worry about expensive cryogenic attacks - three letter guys would extract your key with a wrench.

    I mean the change is bad - it undermines already damaged trust, but the "average Joe" is extremely unlikely to be affected directly.

    There are many much cheaper ways to force you to give up your keys.

  • If they have liquid nitrogen and a memory dumping boot disk, or a memory bus interceptor.
  • Physical Access to a computer is almost always the fastest and easiest way to crack it down. Additionally, both Windows's BitLocker and Linux's dm-crypt are data at "rest" encryption. They are not responsible for the safety when your machine boots up. MAC and user password are the proper method when it's running.
  • I had this enabled as it protects against RAMbleed/ECC errors, so it's not limited to physical attacks.
  • Are you sure? I thought it's just AES without any authentication.
  • It's pretty crazy that we have this entire segment of features that companies artificially restrict from the average person and overinflate the price of, for no real reason. GPU virtualization is another example of such a feature.

    The market segmentation arguments don't really work either, enterprises are paying the big bucks for more than just these standalone features.

  • I think intel tried to offer GPU virtualisation with their consumer offerings but not sure what happened to that.
  • I'm ok with a version of this as a concept. The version being when a feature is technically present in every SKU, but requires an extra purchase to unlock. A reply to you specifically mentioned subscriptions, which I very much do not like (except in cases where the feature requires ongoing costs), but there are many cases where having every version contain the feature, but requiring a purchase to unlock it is pro-consumer, and is a win-win-win (or at wist a win-win-draw). It can, under the right circumstances, allow the product to be available for a cheaper cost than it would otherwise be. So people who are willing to pay for it are better off, people who aren't willing to pay for maintain the option to change their mind for a nominal fee, and the company probably makes slightly more profit.

    All that being said, in my opinion, it needs to come with several features:

    1. no subscriptions for something that is just a one time unlock 2. It needs to be legal and protected for customers to figure out how to unlock it on their own without purchasing the unlock.

    I haven't thought enough to have a strong opinion on the exact situation you describe (where it is present and an unlock isn't available at any fee), other than to say I'd still argue strongly that customers figuring out how to unlock it on their own should be legally protected.

  • Reminds me of subscription heated seats in bmw cars. The hardware is already there, you paid for it and you can’t use it unless you give the automaker a revenue stream on top of the tens of thousands you already paid for the car.
  • From yesterday: "Users cry foul after AMD stripped memory crypto from its consumer CPUs", https://arstechnica.com/security/2026/06/users-cry-foul-afte... ( https://news.ycombinator.com/item?id=48559827 )
  • This was never marketed as a feature of the consumer CPUs and if some malignant actor does get physical access to my (consumer) hardware, then them being able to read out bytes through cryo-freezing the RAM really isn't high up on the list of things I'm going to worry about.
    by thg
  • So that burn notice episode about freezing ram is real? Damn, thought they made it up
  • Many many people use consumer CPUs for gaming servers.
  • Additionally, if you look at the changelogs for old ABL, it seems like this policy decision (only supporting for PRO SKUs) has always been implemented in firmware:

    https://github.com/amd/firmware_binaries/blob/main/cezanne/P...

    AFAICT the situation here is, it should have never been enabled for these consumer parts in the first place.

  • This doesn't matter; it's post-sale enshittification... They didn't even wait to make the next model shittier!

    Also, it probably wasn't the selling point, but it was the baseline of quality, and probably documented online or in manuals.

    Furthermore, accepting this as normal opens the door to further post-sale enshittification of ALL things. Next thing you know, upgrades here and there are going to degrade the quality of products and services just because it wasn't explicitly written (think post-upgrade slowdowns of mobile phones to pressure people to buy newer ones).

    This is THE slipperiest slope; and it's just taking place because the deregulation mafia is turning a blind eye to these tech cartels.

  • There's plenty of features in products I buy which aren't "marketed", which I nonetheless get upset if are suddenly removed.
  • Transparent communication would have been appreciated nonetheless. You have customers not just lawyers on the other side, it's not just about making sure you're legally covered.
  • It's more than just for cryo-freezing and attacks like that, it also helps defend against row-hammer and other DRAM refresh related issues since the scrambling means that the host kernel or application can't determine what the physical bits on the chips are going to actually be and end up determining the layout in a way to flip specific bits. It might still be possible but it's yet another layer of defense against memory related security problems.