evenwicht
@evenwicht@lemmy.sdf.org
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 2 days ago:
dismissing everyone that disagrees with you.
What’s being dismissed is irrelevant facts. You continue (for a 3rd time) to still fail to grasp the fact that Meltdown was not found to affect AMD chips. It’s wholly irrelevant.
Spectre was a kernel patch, so in firmware.
Those are two different things. There was a firmware patch. And separately there was a kernel mitigation. You don’t need both.
Only AMD bothered to fix chips that fit within your timeframe. The fix has not been made for the chips you want to use.
You mean AMD’s f/w patch was not made. Yet you’ve been told about the 15h.org project. If you absorbed that, then citation needed that Coreboot fails to mitigate. In the absence of Coreboot, the os mitigation was implemented in linux. So you’re pushing a bullshit problem.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 2 days ago:
No, you weren’t. You were being pedantic.
If you don’t like the facts, what more is there to say? The facts failed to support your claims. If you will not let the facts shape your world view, then it’s on you to go off and find different facts.
No, I wasn’t. Stop putting words in my mouth.
Nonsense.
Unless you know how to write microcode, I have serious doubts that you are capable of successfully patching the vulnerabilities on those chips.
How are you still failing grasp this? The fix was made. And it was done without writing microcode. You don’t even have to patch Meltdown on chips unaffected by Meltdown (AMD). The spychip failed to protect from both Meltdown and Spectre.
Patching is not the only way to control for a vuln. I am not going to give you the whole infosec discipline here in this thread. There are many ways to controlling for a vuln apart from patching. Depending on your threat model and use cases, there may be no need to do any control.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 2 days ago:
It’s not about me. I already found a pre-spychip laptop at a street market for under $£€ 10. It’s about global e-waste of useful goods and the ignorance driving it.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 2 days ago:
Lashing out at me was unnecessary.
It was an attack on your bullshit. Not on you personally.
I was pointing out that there are 2 catastrophic vulnerabilities that are guaranteed to be present in every chip that meets your criteria.
And I was pointing out that you are wrong.
I’m pointing out that the chips that you want to use have been unsupported for so long that they have catastrophic vulnerabilities that have never even been attempted to be patched.
You are advocating for chips that are /more/ vulnerable, not less. You are advocating for chips with a much larger attack surface and unknown vulns. Overall, you are giving poor advice from an infosec standpoint.
There are more catastrophic vulnerabilities than just Spectre and Meltdown.
I’m waiting.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
Sounds like most PCs today
Bingo. Avoiding it requires either an old machine or an IBM Power 9 chip (which is relatively modern).
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
None of this obviates my thesis. A profit limit of $999,999 in your country reflects a buffer for ops. That’s has no material relevance here. Nor does it support the other Cloudflare user who claimed the charity activity of selling old machines is not viable. To claim that it’s not possible to sell old machines (even at a loss) and yet sustain, this makes it hard to believe you really know how non-profits work.
Indeed it is well known that non-profits have countless angles for abuse. People like Peter Thiel and other right-wing pricks notoriously abuse non-profit charity structure. That’s mostly irrelevant but to the extent that it’s relevant it actually supports my thesis nonetheless.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
“Meltdown affects Intel x86 microprocessors, IBM Power microprocessors,[1] and some ARM-based microprocessors”
I don’t see AMD on that list. Do you?
“At the time of disclosure (2018), this included all devices running any but the most recent and patched versions of iOS,[5] Linux,[6][7] macOS,[5] or Windows.”
So this vuln can be fixed by patching OS kernels, and your reaction is to switch to a CPU that runs embedded closed-source software controlled by a corporate third party who decides what is authorized to execute on your own system? You can fix the problem with or without being nannied.
Spectre affected “All pre-2019 microprocessors”. So no, the spy chip did not protect you. Intel injected the spychip from 2008 forward and AMD did it from 2013 forward.
More generally, it’s not smart infosec to introduce complexity. It’s profoundly naive to stick a big attack surface in the core of your CPU. I think it’s quite well established that vulns exploit defects, and defects are proportional to complexity. Signing up for a closed source blob in the core of your processor is far from wise.
The /chase the shiny/ mentality neglects the fact that you sign up for the worst kind of vulns – the unknown variety. With old gear the vulns are more of the known variety, which you have a fighting chance of controlling for.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
Microprocessors embedded within a microprocessor which either facilitate remote access or impose closed source software.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
A charity still needs to turn a profit or they won’t be a charity for long.
Nonsense. By law, they /must/ break even.
The point is that they make enough money from reselling these things that they can offer some sort of service.
That’s only partially true. If the sales activity is unrelated to the mission, then the sales must support something else. If the mission is environmental, then your claim falls apart.
And by people I only mean the ones shopping there. Not the “mainstream masses”.
It’s one in the same. I would shop there if they had what I wanted. But I don’t shop there because they are only targeting the mainstream masses.
Its a charity shop, not Microcenter or Amazon.
Exactly. It’s bizarre that you can realize this while simultaneously rely on them behaving like a Microcenter or Amazon.
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
2013
- Comment on Local charity shop rejects pre-spychip PCs. Then they get destroyed. 3 days ago:
Correction:
They likely are only selling what
peoplethe mainstream masses want to buy.Smart consumers are marginalised. Just as they are with most of the ensitified market.
Correction:
Just the way
the worldcapitalism works.But we are talking about a charity. I was not talking about a profit-driven company.
It tends to cost money to send them some where they actually want those.
I am willing to pick them up. They are not willing to maintain a list of hardware sought by people. Until we pull levers and twist arms to get a registry of parts sought and who to contact. The price I would pay exceeds the cost of paying their staff to enter a database record and cross-reference what arrives.
- Submitted 3 days ago to retrocomputing@lemmy.sdf.org | 32 comments
- Comment on Possible AMD chips that were spychip-free as late as 2016 5 days ago:
I’m not sure what you’re asking here. The chip you refer to is an 8 core CPU with a tdp of 125W. It is 15h gen2 “Vishera” based on piledriver. I think it’s expected to not have a spy chip. It is not among the questionable/disputed groups of chips.
- Comment on cannot find !Android@thelemmy.club 6 days ago:
Pinging @iso@lemy.lol (the mod of lemmyfederate@lemy.lol, which is a less restrictive Cloudflare node).
- Comment on cannot find !Android@thelemmy.club 6 days ago:
Your reply doesn’t follow. I believe
NOT_ALLOWEDimplies that lemmy.sdf.org defederated from thelemmy.club. Along with others:europe.pub NOT_ALLOWED fedia.io NOT_ALLOWED hackingne.ws NOT_ALLOWED indie-ver.se NOT_ALLOWED lemmy.nz NOT_ALLOWED lemmy.sdf.org NOT_ALLOWED lemmy.world NOT_ALLOWED lemmynsfw.com NOT_ALLOWED news.abolish.capital NOT_ALLOWED pawb.social NOT_ALLOWED quokk.au NOT_ALLOWED suppo.fi NOT_ALLOWED
- Comment on cannot find !Android@thelemmy.club 6 days ago:
That was my first thought but I can never remember how to check that. Then I had a look at one of my fedi scripts and realised I already wrote the code to work that out. Wow… I hate when I write some useful code then forget that I even have it.
So indeed you are correct. My script to find relationships to a community piped to
grep ‘(sdf|lemmy.ml)’yields:lemmy.sdf.org NOT_ALLOWED lemmy.ml NOT_AVAILABLE
That’s from the lemmy-federate.com dataset. I guess NOT_AVAILABLE means the db does not know whether lemmy.ml federates or defederates with that community.
I’ve never used a phone app for lemmy so I’m not familiar with your search tool. Interesting that it supports multiple accounts and searches all of them.
- Submitted 1 week ago to sdfpubnix@lemmy.sdf.org | 8 comments
- Comment on Possible AMD chips that were spychip-free as late as 2016 2 weeks ago:
But, for your mental and social health, you should really maybe take a step back, clear your mind, and read some of the things that are here.
That advice is good for the pragmatist who does not give a shit about ethics.
The horse your riding on is so high, I’m not even sure you can see the grass, let alone touch it.
This is not how you convince ethical consumers to ditch ethics and take the pragmatic selfish path. Ethical consumers do not patronize enshitifiers.
The intentional use of inflammatory language, the not actually answering a question,
The question was irrelevant threadcrap. You need to lower your expectations when you bring uncivil commentary.
and the fact that you’re about a hop skip and jump from actually saying “DO YOUR OWN RESEARCH!”
It’s more like: GET YOUR OWN THREAD.
You are only a stone’s throw from a Truther or other fun conspiracy nut.
This is exactly how normies view those w/infosec backgrounds. We opt for security by default and require justified cause to make a compromise. The normie mindset is to flip that around and prioritize convenience while requiring a reason to do security.
- Comment on Possible AMD chips that were spychip-free as late as 2016 2 weeks ago:
Worth noting that I have seen the “good news” outlets, and I have to say it’s a bit depressing to see how insignificant the news is. It’s never going to be something like “Trump falls out of a helicoptor”. It’s more like “duck tangled in fish line gets rescued”.
- Comment on Possible AMD chips that were spychip-free as late as 2016 2 weeks ago:
The official reason for the intel ME (the intel version of AMD’s PSP which hit in 2008) is so corporations could do some remote management ops on their corporate laptops, and so malware is hindered if it tries to insert itself into the bootstrap and so employees cannot install their own OS or whatever. Of course there is nothing controversial about those scenarios. Something like 99% of intel’s clientel is corporate. The individual human beings who buy personal computers for their own non-business use are in the 1% that mean nothing to intel. So of course their needs can be neglected. Only the corporate consumer matters to the bottom line.
Corporations don’t give a shit about closed-source software. To them, accountability is paramount. And they have that. If the closed-source software does something nasty to them, managers can point fingers. Corporate lawyers can sue. If some shitty proprietary closed-source software is used against some individual, no one gives a shit. Hence why some of us like our FOSS. Transparency and control is more important than accountability to individual human beings. I don’t want some closed-source garbage deciding at the hand of some remote corporation what bootstrap is “authorized”. If you run MS Windows, none of this matters to you.
- Comment on Possible AMD chips that were spychip-free as late as 2016 2 weeks ago:
“Spy chip” is not a claim. It’s nomenclature. I am referring to the PSP. You don’t have to call it a “spy chip” if you don’t want. You can call it “friendly alternate control mechanism”, or “helpful nanny”, if you want.
So from there, what is a credible source for language, when the language is English? It’s not like Academy Français, which officially recrognizes words in the French language. English is more chaotic. If a lot of people are using a word or phrase, journalists will use it. If journalists are using a word frequently, maybe Oxford dictionary or Marriam Webster will add it to their dictionary. If you are American, you may not consider Oxford dictionary credible. And if you are British, you may not consider Webster’s dictionary credible.
- Submitted 2 weeks ago to retrocomputing@lemmy.sdf.org | 15 comments
- Comment on Model numbers for laptops by MSI, Acer, and ASUS need a secret decoder ring.. anyone know the secret meanings? 3 weeks ago:
Generally AMD had a poor reputation so indeed AMD chips ended up in budget product lines. But the tables have turned retrospectively because no one realised from 2008 to 2013 that AMD unwittingly had a pro-consumer privacy advantage, however accidental.
Unfortunately nobody ever put AMDs APUs into actually good laptops,
The CPU is part of what makes a machine “good”. You could say Thinkpads were good for their repairability, upgradability, and stability of design across models – exactly the factors that Apple is the poorest at. If good means /rugged/, then in fact there are some ASUS, Acer, and non-thinkpad Lenovos that had a stainless steel chassis (with pre-spychip AMDs).
Conneseurs of the time would not care to track the various models of perceived junk. But retrospectively it started making sense to do so – once knowledge of the spy chips was well established. But this is a very niche community who gives a shit about spy chips. Masses of normies just care about specs and performance which is who we would rely on to document the hardware.
- Submitted 3 weeks ago to retrocomputing@lemmy.sdf.org | 2 comments
- Comment on Laptop specs dataset wanted. Would be useful to find 2012—14 Windows 8 era laptops. 4 weeks ago:
That’s something different. The PSP is separate and runs parallel to the TPM. The two coexist because they serve different purposes. “As of 2025, a TPM is provided by nearly all PC and notebook manufacturers in their products.” So 12 years following the introduction of the PSP, the TPM is still in play.
I thought the TPM was relatively innocuous for those not running oppressive software. But perhaps I should revisit this, considering this from wikipedia:
“In 2015, Richard Stallman suggested replacing the term “trusted computing” with the term “treacherous computing” due to the danger that the computer can be made to systematically disobey its owner if the cryptographical keys are kept secret from them.”
I previously thought TPM had no remote relationships. But remote attestation is certainly an anti-feature if the hardware can talk to the cloud without the control of users on a FOSS platform. Is that the concern that you have? I need to get a handle on this.
- Comment on Laptop specs dataset wanted. Would be useful to find 2012—14 Windows 8 era laptops. 4 weeks ago:
Perhaps you need uMatrix to go far enough to trigger their protectionism.
- Submitted 4 weeks ago to retrocomputing@lemmy.sdf.org | 5 comments
- Submitted 1 month ago to retrocomputing@lemmy.sdf.org | 4 comments
- Comment on Cannot create new communities 1 month ago:
The community is the first of its kind. There is nothing in the fedi with the same name, past or present.