No privacy orgs have bothered to test and publish AMD CPUs that were made in 2013 which were not compromised by AMD’s PSP. This means if you want to avoid the spychip, you’re compelled to undertake a project of sorting through guesswork, heresay, and vague documents. AMD only vaguely identifies some microarchitectures that have the PSP. There is conflicting information about whether the Kaveri APUs have spychips.

And from there, even if you have a concrete list of chips, laptop and desktop manufacturers have scrubbed their websites of useful specs of that time period because they only want you to buy their new products. So it’s hard to know which machines have the precious resource of a trustworthy CPU.

If a privacy org or FOSS org were to investigate and publish lists of spychip-free processors and also lists of devices that contained those chips (perhaps in collaboration with an eco org like Greenpeace), it would drive up demand for machines that are being discarded for being “too old”. It would inspire some consumers to acquire or hang on to used machines rather than buy something newly enshitified.

  • daveyOsborn@infosec.pubOP
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    37 minutes ago

    Arm has trustzone, so you can’t simply nix x86 chips and be done with it. We would need to do the same research for arm chips.

    This means we could create a demand for old phones by separating those without spychips from the rest. Although it’s a bit sketchy when considering all phones have a dodgy gsm stack designed for remote compromise, IIUC. Maybe Osmocom neutralizes it - not sure.