No privacy orgs have bothered to test and publish AMD CPUs that were made in 2013 which were not compromised by AMD’s PSP. This means if you want to avoid the spychip, you’re compelled to undertake a project of sorting through guesswork, heresay, and vague documents. AMD only vaguely identifies some microarchitectures that have the PSP. There is conflicting information about whether the Kaveri APUs have spychips.

And from there, even if you have a concrete list of chips, laptop and desktop manufacturers have scrubbed their websites of useful specs of that time period because they only want you to buy their new products. So it’s hard to know which machines have the precious resource of a trustworthy CPU.

If a privacy org or FOSS org were to investigate and publish lists of spychip-free processors and also lists of devices that contained those chips (perhaps in collaboration with an eco org like Greenpeace), it would drive up demand for machines that are being discarded for being “too old”. It would inspire some consumers to acquire or hang on to used machines rather than buy something newly enshitified.

  • grue@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    4 days ago

    In case anybody was wondering, AFAIK the fastest non-compromised PC ever made was a dual-socket Opteron 63xx system with an Asus KGPE-D16 running Libreboot.

    (Some people might quibble about which 63xx CPUs are best, as there’s a clock speed vs. core count tradeoff to be made.)

    • daveyOsborn@infosec.pubOP
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      2 days ago

      They are microprocessors embedded within the microprocessor. Intel’s IME enables remote access (by intel’s own admission). If you are not a corporation who manages a fleet of machines, the backdoor can only be used against you. AMD’s variant called the PSP is similar but closed-source. We don’t really have a complete picture of the extent of the compromise with AMD because of the opacity of it (as AMD proactively denied a request for source code). What we don’t know /can/ hurt us, as we already got stung by a defective driver for the AMD’s PSP.

      Even if the spychips were to be hypothetically designed to be aligned with the interests of non-corporate individual consumers, there is no such thing as bug-free software. They have added complexity that works against us and brings vulnerabilities. And we also cannot dispense of the deliberate design whereby some remote actor decides for the user what software is or is not “authorised” to execute. I alone should decide what is authorised on my PC.

      So the fix is to use an AMD processor made before ~2014 (roughly speaking), or a pre-2009 intel. AMD chips were behind intel in terms of performance, but probably not 5 years behind. So I figure 2013 AMDs are the most interesting. But we only have a fuzzy idea of which AMD chips are spychip-free.

  • budget_biochemist@slrpnk.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 days ago

    There’s also all the non-x86 architectures to choose from too. There are x86-on-arm emulators in development to run Windows games. Many discarded old phones just have battery issues and have a perfectly good CPU and RAM.

    • daveyOsborn@infosec.pubOP
      link
      fedilink
      arrow-up
      5
      ·
      edit-2
      4 days ago

      Arm has trustzone, so you can’t simply nix x86 chips and be done with it. We would need to do the same research for arm chips.

      This means we could create a demand for old phones by separating those without spychips from the rest. Although it’s a bit sketchy when considering all phones have a dodgy gsm stack designed for remote compromise, IIUC. Maybe Osmocom neutralizes it - not sure.