cross-posted from: https://lemmy.sdf.org/post/58764195

I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.

So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.

It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.

  • Tiresia@slrpnk.net
    link
    fedilink
    arrow-up
    6
    ·
    15 hours ago

    That sounds like it makes perfect sense from a high security culture standpoint. It is unknown and from an outside power, therefore it is presumed unsafe.

    Of course right now there are a hundred reasons why you should never trust a computer to be private, but I don’t see a problem with trying to make that a hundred minus one if that’s what someone enjoys doing.

    • Bane_Killgrind@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      15 hours ago

      In the context of using this to punch down at a non-profit I can see some reasons.

      OP is not a state level target, the consequences of them getting hacked is they home to make a police report and close some bank accounts. The non profit is not concerned with OP being targeted by the US government, their goal is to provide serviceable computers to needy people.

      It’s surface level relevant to the zero waste conversation, but only if you don’t value anything but the old outdated PC. Older processors like this have such bad processing efficiency that the energy savings alone would pay for a new SBC in a year, presuming heavy use. Then there are the logistical costs and labor of managing that supply of old equipment. A few generations of architecture mean that peripheral and add-in cards are not available or wouldn’t work. The dwindling stock of donor equipment means that the resources to even assemble a working order PC will be higher than newer equipment.

      There’s the same arguments to be had about older refrigeration equipment. Yes, it’s probably better to keep it serviced, but as soon as a big problem comes along a newer more efficient unit should be installed.

      • evenwicht@lemmy.sdf.orgOP
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        edit-2
        6 hours ago

        In the context of using this to punch down at a non-profit I can see some reasons.

        The non-profit was not named, so your abusive hyperbole is obvious.

        The msg exposes a trend likely occuring at many tech shops by charities who have not figured out how to market pre-spychip machines and likely don’t even have the awareness to know what they are tossing which is being blindly scrapped on the simple basis of age alone.

        OP is not a state level target,

        As already pointed out, you need not be targeted by feds doing tailored ops:

        https://hackaday.com/2021/10/01/flaw-in-amd-platform-security-processor-affects-millions-of-computers/

        The non profit is not concerned with OP being targeted by the US government, their goal is to provide serviceable computers to needy people.

        This is a false dichotomy. Needy people should have security too. It also misses an important infosec principle: the principle of least privilege. If you don’t need an extra attack surface, it’s unwise to deploy it.

        It’s surface level relevant to the zero waste conversation, but only if you don’t value anything but the old outdated PC.

        Nonsense. Zero waste of hardware that serves a variety of purposes does not exclude any other zero waste practice.

        Older processors like this have such bad processing efficiency that the energy savings alone would pay for a new SBC in a year, presuming heavy use.

        How foolish of you to presume heavy use on an arbitrary unknown demographic of users.

        Then there are the logistical costs and labor of managing that supply of old equipment.

        Perhaps you are in a country where they just toss e-waste into a landfill. In more responsible parts of the world, the logistical costs and labor of properly dispensing the old e-waste is /higher/ than the cost of selling it to a buyer who will use it.

        A few generations of architecture mean that peripheral and add-in cards are not available or wouldn’t work.

        Blaming designed obsolescence on the older hardware when interoperability matters – amusing, if you only knew that USB 3 is backwards compatible with USB 2 and that gigabit ethernet is backwards compatible with its predecessor. There is also an absurdity with refusing to buy something designed for upgrades on the basis of /something/ being incompatible, when in fact the new hardware is dispensing of older standards. New laptops are soldering in RAM and if the battery is not soldered in it’s not using standard replaceable cells but rather proprietary batteries that amount to designed obsolescence. Copious cheap old upgrades can be trivially acquired when chronic upgraders dispense of their old gear.

        The street market is flooded with old RAM at dirt cheap prices. We don’t need factory new RAM to upgrade our gear.

        A 2008 thinkpad is what I use today, after 18 years. The shit you are advocating now has little chance of being usable 18 years from now as the designed obsolescence has evolved and enshitification of products have become increasingly insideous.

        The dwindling stock of donor equipment

        There is no shortage. It’s the thesis in fact. So much donor equipment is coming in that they must be selective.

        Apart from failing to grasp the infosec factor, by fixating on security likely as a not-so-ethical consumer yourself you missed the fact that some consumers simply oppose anti-consumer products even if they don’t give a rat’s ass about security. Individual non-corporate consumers are being pushed to buy products that were made for corps and work against their interests generally.

        • Bane_Killgrind@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 hours ago

          to market pre-spychip machines

          Every processor and Soc manufactured since 2012 has some form of security subprocessor, or TPM, or something that you are classifying as a made up term, and which you won’t acknowledge are not black boxes across the board like you seem to be implying.

          You are wrong about the tech and fearmongering, and you seem entitled.

          If you offered the non -profit your time to curate these parts that would be great, or if you seemed more interested in learning then derisive that would have also have been great.

          • evenwicht@lemmy.sdf.orgOP
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            edit-2
            6 hours ago

            Every processor and Soc manufactured since 2012 has some form of security subprocessor, or TPM, or something that you are classifying as a made up term, and which you won’t acknowledge are not black boxes across the board like you seem to be implying.

            TPM is a different but similar problem. It’s unclear why you are falsely claiming that I will not acknowledge what they are. Where do you get that from?

            (edit) I would be in favor of a charity shop also stocking a few pre-TPM laptops.

            You are wrong about the tech and fearmongering, and you seem entitled.

            I believe you are wrong about the tech and pushing cavalier disregard for wise infosec principles on the basis that you think the spychip can only be exploited by a nation state doing tailored ops. You lack some basic knowledge about bugs.

            If you offered the non -profit your time to curate these parts that would be great,

            This is not mutually exclusive to exposing inefficiencies. It’s wholly irrelevant to the thread.

            (edit) I am exposing a trend that is likely global. If I were to volunteer in my local shop, I would still be exposing this problem. And you would still be taking the cavalier stance that running a spychip is a wise practice if not specifically targeted by a threat agent.

            or if you seemed more interested in learning

            I did not mean to block you from proving that only a nation state can exploit the spychip. Feel free to educate me.

            • Bane_Killgrind@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              5 hours ago

              https://lemmy.dbzer0.com/post/75183544/28016093

              will not acknowledge what they are. Where do you get that from?

              That comment.

              spychip can only be exploited by a nation state doing tailored ops.

              Exploiting these things is only necessary in those kinds of ops, to bypass regular auditing or something like that. Your machine would already be tipped over, top would have admin access by the time someone was hiding a payload in there.

              But ok you want a computer that has well documented vulnerabilities that will not be patched https://www.tomshardware.com/pc-components/cpus/amd-wont-patch-all-chips-affected-by-severe-data-theft-vulnerability-ryzen-1000-2000-and-3000-will-not-get-patched-among-others

              Edit 8/12/2024 4:45am PT: The researchers who discovered the flaw in AMD’s chips contend that the vulnerability impacts all AMD chips extending back to 2006.

              Good luck tilting at windmills.

              • evenwicht@lemmy.sdf.orgOP
                link
                fedilink
                arrow-up
                1
                ·
                edit-2
                4 hours ago

                That comment.

                What you linked is not my comment.

                Exploiting these things is only necessary in those kinds of ops,

                Nonsense. Any botnet would benefit from exploiting it. The threat is not limited to targeted attack.

                Your machine would already be tipped over,

                Nonsense. Intel admits that the IME enables remote access.

                But ok you want a computer that has well documented vulnerabilities

                Of course.

                that will not be patched

                First of all, bullshit to not being patched. 15h chips are still supported in the free world. See 15h.org. Patching is also not the only remedy. There are many different ways to control for a vuln and sometimes a vuln requires no control at all, depending on the use case and threat model.

                • Bane_Killgrind@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  5 hours ago

                  not my comment.

                  Yes I know… It’s how you responded to that

                  Are you just a chatbot that’s prompted to be contrarian or something???

                  • evenwicht@lemmy.sdf.orgOP
                    link
                    fedilink
                    arrow-up
                    1
                    ·
                    edit-2
                    4 hours ago

                    Nothing in my response to that post expresses or even implies an acceptance of TPMs.

                    Are you just a chatbot that’s prompted to be contrarian or something???

                    Your inability to simply directly quote what you are claiming is more characteristic of a chatbot. Why can’t you quote my words that lead you to believe I have endorsed TPMs?

      • Tiresia@slrpnk.net
        link
        fedilink
        arrow-up
        6
        ·
        11 hours ago

        Disliking OP is reason enough to want them out of your feed, you don’t have to try to get them by gatekeeping what counts as zerowaste or what counts as valid activism/hobbies. You can just block them and move on.

        OP is not a state level target, […]

        That’s a very individualist attitude. Even if OOP is doing nothing to combat the rise of fascism, the chip issue affects everyone, including investigative journalists, activists, and others that might get state-level attention without having state-level resources (i.e. being dependent on the likes of random charity shops).

        It’s surface level relevant to the zero waste conversation […]

        This reasoning applies equally well to other “waste reduction” hobby projects like spending hours of labor (thus “wasting” the resources it takes to keep a person alive) to fix up an old article of clothing that would otherwise have been discarded, which you could simply have replaced with new mass-produced (and therefore resource-efficient) stuff.

        If you genuinely want stuff that wastes labor - like getting ancient computers to work, mending clothes, or high-context living - gone from this community, that is a consistent opinion and we can talk about that.

        • Bane_Killgrind@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          8 hours ago

          For the individualist thing… If there are these concerns, OP should not be just rolling his own jank setup to do his work. There are groups that could provide him with secure hardware or validate the hardware he can get.

          I checked and the h16 processor they mentioned uses an Arm a5 core for trustzone functions. There are tools to audit that.

          All of this is unreasonable for a charity junk shop.

          • evenwicht@lemmy.sdf.orgOP
            link
            fedilink
            arrow-up
            2
            arrow-down
            1
            ·
            7 hours ago

            OP should not be just rolling his own jank setup to do his work. There are groups that could provide him with secure hardware or validate the hardware he can get.

            You should stop trying to block the zero waste movement and stop trying to make people dependent on others.

            I checked and the h16 processor they mentioned uses an Arm a5 core for trustzone functions. There are tools to audit that.

            You mean the 16h, I suppose. Tools to audit that the closed source software does what I want? That’s amusing for sure. I wonder by what magic I’m not permitted to see the code but I can use probably another closed-source blob to verify whether my boot-licking product is doing what /the maker/ intends.

            Your comment is useful but just not how you intended. The tools to audit the trustzone functions would at least tell me whether a spychip is present, so I can avoid it.

        • Bane_Killgrind@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          8 hours ago

          spending hours of labor

          I have no problem with people spending their own labor time.

          I do have a problem with dictating how a charity spends their labor time, specifically in a way that would reduce their ability to provide services. If OP offered their labor to handle this consistently for the charity, I missed that.

          • evenwicht@lemmy.sdf.orgOP
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            6 hours ago

            I do have a problem with dictating how a charity spends their labor time,

            Failing to inform yourself about how a charity operates and to oppose the sharing of that info is utter foolishness. To oppose identifying problems, exposure of them, and making improvements is essentially openly hostile to social advancement.

            It’s sloppy and reckless to neglect to do some basic homework before selecting charities to support. If they are being needlessly wasteful, they are inefficient.

            specifically in a way that would reduce their ability to provide services.

            It’s the contrary. Sales facilitates provision of services. You’re advocating needless waste.

            If OP offered their labor to handle this consistently for the charity, I missed that.

            Probably what you missed was that a customer was in the shop with money and prepared to spend it, but couldn’t because the shop manager made a poor decision on what to accept from donors.

            • Bane_Killgrind@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              6 hours ago

              Sales facilitates provision of services.

              Maintaining a product takes time and space. The lowest margin, least power efficient, and least in demand items cost the same to sell as everything else that’s easier to sell.

              They made a decision about resources.

              • evenwicht@lemmy.sdf.orgOP
                link
                fedilink
                arrow-up
                1
                arrow-down
                1
                ·
                6 hours ago

                Correction:

                They made an uninformed decision about resources.

                You will have a hard time convincing me that they thought this through: “these 2013 AMD laptops are pre-spychip, so we could save a few of the latest pre-spychip models and advertise them as pre-spychip to boost interest”.

                • Bane_Killgrind@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  6 hours ago

                  Your spychip thing is a made up problem.

                  The distinction is several processor architectures and compatibility.

                  Go ask them to give your number to the next person they turn away.

                  • evenwicht@lemmy.sdf.orgOP
                    link
                    fedilink
                    arrow-up
                    1
                    arrow-down
                    1
                    ·
                    edit-2
                    5 hours ago

                    Your spychip thing is a made up problem.

                    It’s on you to debunk the evidence that has been established. You are free to post counter evidence. No one is stopping you.

                    The distinction is several processor architectures and compatibility.

                    Luckily we need not upgrade the processor because that is precisely the thing we are keeping back. And we need not upgrade the motherboard in countless different collections of use cases, thanks largely to backwards compatibility.

                    Go ask them to give your number to the next person they turn away.

                    I did. One of my local charities already knows what I am looking for. OTOH, they are not diligent. I walked into the shop once and found items they said they would contact me on. This is also not a me problem. It’s a global problem. Your ad hoc idea for just one person will not solve the problem of thousands of pre-spychip machines being needlessly destroyed.

                    (edit) But I must say it’s a bad idea to for the individual charities to have that task. The public waste management collects the e-waste and distributes to charities what can be used. A DB of what spare parts people need should be implemented at the central point of the collection first and foremost. Getting every charity in the loop would be a good evolution from there but it should start centrally.