cross-posted from: https://lemmy.sdf.org/post/58764195

I was in the non-profit shop of a local charity. They accept donations of used computers then resell them to the public. The profit goes to charity. I asked for their oldest machine. It had an AMD chip from the 16h family. Thus, a spychip.

So their oldest machine was still too new for me. I asked why don’t you have anything older? They said the general public would not accept anything older, and so the shop also does not accept anything older. When machines are rejected, they go to a factory that destroys them and recovers the raw metals.

It’s sad to see that pre-spychip machines are being destroyed and that even 2nd-hand customers are being limited to anti-consumer spychip hardware.

  • Bane_Killgrind@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 hours ago

    to market pre-spychip machines

    Every processor and Soc manufactured since 2012 has some form of security subprocessor, or TPM, or something that you are classifying as a made up term, and which you won’t acknowledge are not black boxes across the board like you seem to be implying.

    You are wrong about the tech and fearmongering, and you seem entitled.

    If you offered the non -profit your time to curate these parts that would be great, or if you seemed more interested in learning then derisive that would have also have been great.

    • evenwicht@lemmy.sdf.orgOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      edit-2
      6 hours ago

      Every processor and Soc manufactured since 2012 has some form of security subprocessor, or TPM, or something that you are classifying as a made up term, and which you won’t acknowledge are not black boxes across the board like you seem to be implying.

      TPM is a different but similar problem. It’s unclear why you are falsely claiming that I will not acknowledge what they are. Where do you get that from?

      (edit) I would be in favor of a charity shop also stocking a few pre-TPM laptops.

      You are wrong about the tech and fearmongering, and you seem entitled.

      I believe you are wrong about the tech and pushing cavalier disregard for wise infosec principles on the basis that you think the spychip can only be exploited by a nation state doing tailored ops. You lack some basic knowledge about bugs.

      If you offered the non -profit your time to curate these parts that would be great,

      This is not mutually exclusive to exposing inefficiencies. It’s wholly irrelevant to the thread.

      (edit) I am exposing a trend that is likely global. If I were to volunteer in my local shop, I would still be exposing this problem. And you would still be taking the cavalier stance that running a spychip is a wise practice if not specifically targeted by a threat agent.

      or if you seemed more interested in learning

      I did not mean to block you from proving that only a nation state can exploit the spychip. Feel free to educate me.

      • Bane_Killgrind@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 hours ago

        https://lemmy.dbzer0.com/post/75183544/28016093

        will not acknowledge what they are. Where do you get that from?

        That comment.

        spychip can only be exploited by a nation state doing tailored ops.

        Exploiting these things is only necessary in those kinds of ops, to bypass regular auditing or something like that. Your machine would already be tipped over, top would have admin access by the time someone was hiding a payload in there.

        But ok you want a computer that has well documented vulnerabilities that will not be patched https://www.tomshardware.com/pc-components/cpus/amd-wont-patch-all-chips-affected-by-severe-data-theft-vulnerability-ryzen-1000-2000-and-3000-will-not-get-patched-among-others

        Edit 8/12/2024 4:45am PT: The researchers who discovered the flaw in AMD’s chips contend that the vulnerability impacts all AMD chips extending back to 2006.

        Good luck tilting at windmills.

        • evenwicht@lemmy.sdf.orgOP
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          4 hours ago

          That comment.

          What you linked is not my comment.

          Exploiting these things is only necessary in those kinds of ops,

          Nonsense. Any botnet would benefit from exploiting it. The threat is not limited to targeted attack.

          Your machine would already be tipped over,

          Nonsense. Intel admits that the IME enables remote access.

          But ok you want a computer that has well documented vulnerabilities

          Of course.

          that will not be patched

          First of all, bullshit to not being patched. 15h chips are still supported in the free world. See 15h.org. Patching is also not the only remedy. There are many different ways to control for a vuln and sometimes a vuln requires no control at all, depending on the use case and threat model.

          • Bane_Killgrind@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            not my comment.

            Yes I know… It’s how you responded to that

            Are you just a chatbot that’s prompted to be contrarian or something???

            • evenwicht@lemmy.sdf.orgOP
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              4 hours ago

              Nothing in my response to that post expresses or even implies an acceptance of TPMs.

              Are you just a chatbot that’s prompted to be contrarian or something???

              Your inability to simply directly quote what you are claiming is more characteristic of a chatbot. Why can’t you quote my words that lead you to believe I have endorsed TPMs?