• 207 Posts
  • 319 Comments
Joined 2 年前
cake
Cake day: 2024年7月1日

help-circle
  • You seem to be eating up your own red herring quite well. Your own request for irrelevant information led you to a bizarre rabbit hole about power 9 chips. Only to lead you to another bogus claim:

    will only provide limited maintenance on a paid basis. This is the same pain point you have about the AMD processor, but a decade more recent.

    I never said I opposed paid support. The spychip has many shortcomings, only one of which is the dire need for support due to the black box attack surface. The Power 9 is not a spychip. IBM selling support for a non-spychip does not imply that support is needed by all users. Support can be anything from running a compiler to understanding their docs. I don’t have a problem with IBM offering some kind of support for customers that want a bit of pampering and convenience.

    it’s for developers and not consumers in general.

    This is a red herring within a red herring. The power 9 answered your request for information. What you do with the info is on you. I don’t give a shit what you do with the info, because it’s irrelevant. At least to the extent that you have spoken about it. The only shred of relevency would be that the Power 9 is hardly useful to the same demographic who would use a 2013 pre-spychip, so it fails to counter the thesis that pre-spychips shouldn’t be destroyed. The venn diagram of the two demographics of users would look close to this: OO

    So is your expectation the whole market switches to framework laptops with the 3rd party RISC board?

    No. Why would it be? I expect the existing shitshow to carry on. Most consumers are incompetent. Hence why the enshitified marketplace is a business success.


  • Please point to modern processors or SoC available to consumers that does not have these subprocessors.

    The IBM power 9 is one, but it’s red herring anyway because you’re still looking to weasel out of acknowledging that the only relevent comparison is the same chip with and without an spychip. Looking to other chips is nothing more than a futile attempt to hide the fact that spychip is not wasting energy. I doubt you will find an audience naive enough to buy your nonsense… but if you find them, sell them a bridge.

    technology needs change.

    Not this change.

    Again, you are spouting emotional, uninformed garbage.

    Again, your stance is driven by emotion as you continue to fail to justify your closed-source support-needy garbage.

    There is no technical definition of attack surface that would classify commingled processing as better than bifurcated processing.

    It doesn’t need to. An attack surface definition that attempts classification would be a broken definition by someone attempting shenanigans to hide their attack surface. Someone hoping to bullshit consumers who don’t want extra vulns and then being at the mercy of the corporate supplier’s will to fix.

    I honestly believe that you are being paid to post this stuff to sabotage real beneficial collaboration.

    You can test that theory by actually putting forward an effective logical argument that actually justifies your position. You can only blame yourself for failing to articulate a sensible idea.


  • Yes and the things that these chips process used to be processed on the main CPU, relying on software to prevent malicious access.

    Rightfully so.

    Correction to your utter pro-corporate drivel:

    Now the attack surface, which used to be every implementation of every software, is reduced expanded to the unreachable closed-source implementation that makes consumers dependant on a corporate of the world separation with an imbalance of power these chips provide subject consumers to.

    You still aren’t talking about the technology

    The thread was originally about e-waste of technology. Your thread crap has discarded the e-waste discussion, so of course I am talking about technology. This thread branch is about avoiding undisclosed opaque technology with an attack surface we don’t need.

    , you are spouting “common sense” nonsense like new chips using single digit watts of power are less efficient

    The spouting of nonsense comes when you neglect to make a meaningful comparison that actually reveals the waste of the spychip. You can’t hide the spychip’s waste by choosing processors of different effeciencies from different time periods.

    than old chips using dozens of watts of power.

    You missed the link about new machines still using a 2013 pre-spychip because the TDP is 17w. But I guess it hardly matters when you’re trying to make a dishonest comparison anyway to conceal waste.

    Edit: again, what is the cutoff? Should they still support procs from 1995? 1990?

    If it’s a closed-source spychip, it should be supported for as long as the chip maker exists. And when they go under, they should be forced to disclose the source code. If they don’t like that, they should quit making the spychips. If they are ruined and sink because they failed to support their crippled support-needy garbage, then rightfully so.

    If it’s not a spychip, it needs no support from the maker apart from documentation, which should always be available as long as the chip maker exists. And thereafter available on archive.org.





  • Attack surface is reduced with architecture like this. You really don’t know what you are talking about or what problems are addressed with this stuff.

    Bullshit. You really have no clue what you are talking about. The absence of an attack surface is as small as an attack surface gets. When you add something that can be attacked, you are adding an attack surface that was not there before you added it.

    You still seem to think that other people’s resources are infinite,

    On the contrary, you are the one advocating for resource waste. Omitting the spychip uses far fewer resources both for producing and then customer resources for powering it. Then human resources are wasted for controlling the attacks (because you added an attack surface) and for accidental defects (because you added the unnecessary complexity of closed-source software which ensures there is more code that can go wrong and also simultaneously fewer brains reviewing it).

    It’s not just an extra chip. That chip needs a driver. The driver doesn’t write itself. So that takes resources. And that driver creates another point of failure and attack surface. It also requires resources to maintain that driver. And when AMD disregards their “duty of care” because the chip is too old to be profitable thus drops support, the resources of consumers are wasted dealing with the problem (which they should never have had in the first place).

    but this time criticising a corp that should have a duty of care in this regard.

    You sound like a corporate spokesperson for a chip maker. “Duty of care” entails not subjecting your customer to a needless attack surface. What you fail to grasp is the spychip is for corporate customers, not individuals who do not need a closed-source blob in the core of their CPU. Individuals did not ask for a nanny. We requested a CPU that we control ourselves. Forcing us (individuals) to have a nanny we don’t want is a reckless abandonment of duty.


  • One article about a patched vulnerability isn’t special or indicative of anything on a wider scale.

    Of course. The wide-scale big picture thesis is that it’s foolish to needlessly add an attack surface to the core of your CPU. To those who are infosec aware already accept that automatically because it follows from basic prevailing well-established principles of the infosec discipline. We don’t need to wait for the attack surface to be exploited before realising that the attack surface exists. In laymans terms, we lock our doors even if we have never been intruded on.

    The infosec uninformed don’t practice security by default. They favor the most convenient decision (to run the fastest chip) and will not consider security in the absence of a specific exploit. The hackaday article gives that. It does nothing to sway experts who already know it’s rock-stupid to needlessly introduce an attack surface. The hackaday article supports my thesis in the face of those who reject fundamental infosec principles.

    Sounds like they have their shit together.

    AMD abandons customers of their older products. AMD only reacted as they did because the defect was found in recent hardware. If you equate the similar mentality that also brings designed obolescence to “having their shit together”, you can only speak from the standpoint of a shareholder. When a serious 0-day emerges on a 10+ year old AMD spychip, it’s foolish to assume AMD will have their shit together and patch it. They will have their shit together only in terms of the corporate bottom line, not to the ethical extent of protecting /all/ their customers.

    There are plenty examples of AMD not having their shit together, such as refusing to patch Spectre on some of their own products. Introducing the spychip in the first place is not “having their shit together” for the demographic of non-corporate consumers.




  • You started with this false claim:

    which you won’t acknowledge are not black boxes across the board like you seem to be implying.

    The claim is false for two different reasons:

    1. I did not refuse to acknowledge that they are not black boxes.
    2. Some are black boxes, and some are not. It depends on the maker.

    Then despite your failure to directly quote what you think supports your claim, you contradict yourself by claiming a TPM /would/ satisfy my definition that covers closed-source code while simultaneously asserting that TPMs are not black boxes. You need to sort out your brain malfunction and get some consistency.

    It’s bizarre that you make this meaningless yet contradictory speculation in the first place, then attack the speculation because I made no claim about TPMs that you could attack.

    The TPM is hardware constitutes a spychip as far as I’m concerned to the extent that it’s closed-source. But some are not.



  • I can’t believe I’m saying this, and I’m aware of the potential for innuendo here, but I am going to have to ask what you mean by “pegging” a PSU.

    A 65W PSU can supply at most 65W, but it doesn’t “draw 65 watts regardless”. It will draw less than max power if it is using less.

    Yes, indeed. I think we have the same understanding.

    Pegging means the appliance is drawing the max amount of current. As a PC becomes more efficient, the PSU does not shrink. It just gives more calculations for the same energy drawn. But if it’s mostly at idle doing basic tasks like web browsing, there isn’t a notable consumption difference. A 65W PSU was typical two decades ago, and also still today.


  • dismissing everyone that disagrees with you.

    What’s being dismissed is irrelevant facts. You continue (for a 3rd time) to still fail to grasp the fact that Meltdown was not found to affect AMD chips. It’s wholly irrelevant.

    Spectre was a kernel patch, so in firmware.

    Those are two different things. There was a firmware patch. And separately there was a kernel mitigation. You don’t need both.

    Only AMD bothered to fix chips that fit within your timeframe. The fix has not been made for the chips you want to use.

    You mean AMD’s f/w patch was not made. Yet you’ve been told about the 15h.org project. If you absorbed that, then citation needed that Coreboot fails to mitigate. In the absence of Coreboot, the os mitigation was implemented in linux. So you’re pushing a bullshit problem.


  • No, you weren’t. You were being pedantic.

    If you don’t like the facts, what more is there to say? The facts failed to support your claims. If you will not let the facts shape your world view, then it’s on you to go off and find different facts.

    No, I wasn’t. Stop putting words in my mouth.

    Advocating for only running “supported” chips is inherently contempt for old hardware. (But note you said that apparently without knowing about the 15h.org project).

    Unless you know how to write microcode, I have serious doubts that you are capable of successfully patching the vulnerabilities on those chips.

    How are you still failing grasp this? The fix was made. And it was done in the kernel without writing microcode. You’ve been told this already. You did not counter it yet to still failed to absorb it. And now you try recycling defeated arguments. You don’t even have to patch Meltdown on chips unaffected by Meltdown (AMD). The spychip failed to protect from both Meltdown and Spectre.

    Patching is not the only way to control for a vuln. I am not going to give you the whole infosec discipline here in this thread. There are many ways to controlling for a vuln apart from patching. Depending on your threat model and use cases, there may be no need to do any control. The 15h.org project is another kind of control. Air gapping is another. Detecting the malicious code is another.


  • It’s not about me. I already found a pre-spychip laptop at a street market for under $£€ 10. It’s about global e-waste of useful goods and the ignorance driving it. Ignorance that is thick as we can see from an absence of basic infosec principles and people being conditioned to lick boots without questioning the ethics of patronising anti-consumer suppliers.

    Ignorance is not in itself a big problem. It can be corrected if someone is willing to learn. And I can accept arrogance if it’s logically sound and factually correct. But ignorance coupled with pretentious arrogance is a bit intolerable. I don’t give a shit about the egos of such thread crapping responders.


  • But is there any financial justification for a charity shop paying to stock it?

    There is financial justification if they can actually sell it. And of course not if they cannot sell it. We don’t get a crystal ball. It’s a judgement call to predict whether they can sell it. They have opted to be risk averse. The decision was likely made without awareness of pre-spychip characteristics and without considering whether it can be marketed as such. It would be interesting to know if a shop has actually tried that, which can confirm that pre-spychips don’t sell even when marketed as such.

    One of the problems is that the shop cannot handle supporting the public on linux. Independent of hardware performance, they abandoned linux in the store and returned to only selling Windows machines. Their staff turnover was too high to keep training staff on giving linux support.

    Plus the energy cost to run it if you do buy it.

    Energy cost is the same. A 65w PSU that is pegged will draw 65 watts regardless of what it drives. If the hardware is not being heavily tasked and the platform is lean, then there is only a difference on responsiveness but not on energy. Furthermore, some of these pre-spy chips have a TDP of 17w, which is interesting enough that recent machines are still being produced with them:

    https://cputronic.com/index.php/cpu/amd-a4-4355m

    A 17w TDP means it’s efficient enough to be fanless, or to not need to spin a fan often. It’s foolish to let laptops with 17w APUs get tossed when the very same CPU is still going into modern laptops precisely because of their efficient /for the money/.

    Some of the higher TDP chips from the same family are notoriously inefficient. So sellers and buyers need some awareness. In the worst case, an inefficient chip is not so inefficient in a cold region or cold season. We cannot say from 10,000 feet whether such instances would be inefficiently deployed when speaking independant of the regional climate.



  • Man this is some fearmongering.

    The evidence is in front of you. Hackaday.com is publishing facts. These facts do not make you fearful yet you call them fearmongering.

    Dude you are more likely to get viruses and exploited running the older hardware.

    Nonsense. Vulns in the older hardware are mostly of the known variety. New hardware is rich in the unknown variety of vulns, which by their nature you don’t know about and cannot control for.

    I understand that vulnerabilities pop up, but at least the within a decade recent stuff gets patched.

    And new vulns get introduced. Even the patches themselves bring new vulns.


  • I’m involved in a charity that also ends up with a good amount of computer donations. Unfortunately, we have to be ruthless with what we accept. We have to pay to dispose of ewaste.

    Charities paying for the e-waste is not universal. Depends on your local waste management. But nonetheless, when a machine is disposed of /someone/ must pay for it one way or another. It’s cheaper to actually use it.

    In practice, laptops with a dual core processor or higher can be put to use or given a new home.

    The pre-spychip AMDs have anywhere between 2 and 8 cores just before the last segment of 15h chips were made.

    Unless you’re willing to store the computers for them, until a unicorn comes in asking for one, it’s likely a practicality issue.

    It’s a marketing problem. Consumers don’t know to demand pre-spychip machines because they are wholly clueless about it. A charity shop can manufacture demand just by being transparent in their sales info.

    A better option might be to go to a retro gaming shop/cafe. They are more likely to stock old hardware to play older games natively. It’s mostly consoles, but some also have PCs.

    That’s a good idea. Either way, it requires an intervention in the status quo. In my region, the public is blocked from getting access to rejected hardware, which goes straight to the (apparently secret) disposal site.


  • That comment.

    What you linked is not my comment.

    Exploiting these things is only necessary in those kinds of ops,

    Nonsense. Any botnet would benefit from exploiting it. The threat is not limited to targeted attack.

    Your machine would already be tipped over,

    Nonsense. Intel admits that the IME enables remote access.

    But ok you want a computer that has well documented vulnerabilities

    Of course.

    that will not be patched

    First of all, bullshit to not being patched. 15h chips are still supported in the free world. See 15h.org. Patching is also not the only remedy. There are many different ways to control for a vuln and sometimes a vuln requires no control at all, depending on the use case and threat model.



  • Your spychip thing is a made up problem.

    It’s on you to debunk the evidence that has been established. You are free to post counter evidence. No one is stopping you.

    The distinction is several processor architectures and compatibility.

    Luckily we need not upgrade the processor because that is precisely the thing we are keeping back. And we need not upgrade the motherboard in countless different collections of use cases, thanks largely to backwards compatibility.

    Go ask them to give your number to the next person they turn away.

    I did. One of my local charities already knows what I am looking for. OTOH, they are not diligent. I walked into the shop once and found items they said they would contact me on. This is also not a me problem. It’s a global problem. Your ad hoc idea for just one person will not solve the problem of thousands of pre-spychip machines being needlessly destroyed.

    (edit) But I must say it’s a bad idea to for the individual charities to have that task. The public waste management collects the e-waste and distributes to charities what can be used. A DB of what spare parts people need should be implemented at the central point of the collection first and foremost. Getting every charity in the loop would be a good evolution from there but it should start centrally.