by

AMD restores memory encryption

AMD has restored Ryzen memory encryption after users spotted a firmware vasectomy and gave the chipmaker a proper kicking.

Last week, AMD was caught stripping memory encryption from its consumer CPUs without warning. After a social media roasting, the chipmaker now says it will put the protection back.

The feature is Transparent Secure Memory Encryption, or TSME, which AMD often calls Memory Guard. It encrypts data in RAM and helps defend against cold-boot attacks and other physical memory snooping.

The awkward bit is that AMD removed it through firmware. There was no silicon change forcing the move, which made the decision look more like policy than engineering necessity.

According to Ars Technica users were not impressed. They said AMD had quietly removed a protection it had supported for years, leaving customers to discover the downgrade only after poking around with security tools.

The change arrived in a recent firmware update, which meant continued support was largely a matter of will. Critics called on AMD to reverse course rather than shove the feature towards pricier chips.

Over the weekend, AMD changed its mind.

“Regarding certain non-PRO Ryzen 9000-series desktop processors, a BIOS option to enable Memory Guard was previously available but was removed in a recent update,” AMD said in an email. “Based on valuable community feedback, we will reinstate this option in an upcoming BIOS release in July.”

It still does not explain why the protection vanished in the first place. Critics suspect AMD may have tried to push customers towards more expensive CPUs. That would be the usual product segmentation nonsense, only with a security feature caught in the middle.

There could be less grubby explanations. AMD may have struggled with support as chip designs changed, or it may have been chasing performance.

Memory encryption adds latency because data has to be encrypted and decrypted. Gamers, a big chunk of the Ryzen 9000 crowd, tend to treat latency like a personal insult.

Many gamers probably disabled TSME anyway and had little use for it. AMD may have assumed the change would not matter much, which is brave when privacy-minded users exist and have GitHub accounts.

However, removing security protection without telling customers makes every BIOS update look like a lucky dip. AMD is now promising a July BIOS release to restore the option on certain non-PRO Ryzen 9000 desktop processors. The company has yet to say whether the removal was deliberate, accidental or just another firmware brain fart.

 

 

TOPICS:
AGESA firmware  ·  AMD  ·  bios update  ·  cold boot attacks  ·  CPU security  ·  memory encryption  ·  Memory Guard  ·  ryzen 9000  ·  TSME

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews