Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Paul MaudDib posted:

Potentially, if you only have one or two HDDs in your rig, you could do that with Gigabit too, if your mobo has dual NICs or you can add an adapter card. Having a dedicated channel between your main rig and your NAS actually owns pretty hard. Probably not cheaper than IB these days, but maybe more flexible.

All it took was adding a hosts mapping on my gaming rig that said that traffic to the NAS should resolve to a 10.0.x address while my 1Gbase-T network resolves to 192.168.x. And vice versa for the NAS. They can coexist on regular gbit ethernet while also having their own private device-to-device host mapping.

I used to do this with Firewire before gigabit became cheap enough for me :unsmith:

Adbot
ADBOT LOVES YOU

EmpyreanFlux
Mar 1, 2013

The AUDACITY! The IMPUDENCE! The unabated NERVE!

Despite looking at both bios, what does this mean if anything for changes at GloFo? I can't parse why this is important.

PC LOAD LETTER
May 23, 2005
WTF?!
We probably won't know until a year or so down the road when we see if the CEO change results in any difference in the roadmaps.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

How will you know what to attribute to the CEO change?

CapnBry
Jul 15, 2002

I got this goin'
Grimey Drawer

GRINDCORE MEGGIDO posted:

Please post a photo if you can. I want that!
I donated it to Goodwill a couple months after I got back from GDC so somewhere there was a kid totally ripping threads in the AMD Dodge Viper his mom got him from the goodwill store. I checked my photos and couldn't find one of it, and was surprised that when I google image searched for it, there weren't any results for AMD-branded remote control cars. Maybe I had a collector's item! It also might have been 2005 so that would have been pre-merger so it could have been an ATI Dodge Viper which would just be worthless.

chocolateTHUNDER
Jul 19, 2008

GIVE ME ALL YOUR FREE AGENTS

ALL OF THEM
I'm a little confused for some reason; I'm planning on building a Ryzen computer within the next week and just wanna make sure a Ryzen revision isn't due within the next month or two?

Llamadeus
Dec 20, 2005
It is literally due next month.

Shy
Mar 20, 2010

chocolateTHUNDER posted:

I'm a little confused for some reason; I'm planning on building a Ryzen computer within the next week and just wanna make sure a Ryzen revision isn't due within the next month or two?

An update next month.

orcane
Jun 13, 2012

Fun Shoe

chocolateTHUNDER posted:

I'm a little confused for some reason; I'm planning on building a Ryzen computer within the next week and just wanna make sure a Ryzen revision isn't due within the next month or two?

Good news, friend: The Ryzen revision is coming NEXT MONTH.

E: damnit... okay, I have a link at least! https://www.forbes.com/sites/antonyleather/2018/03/12/amd-to-refresh-entire-ryzen-processor-range-in-2018-exciting-news-for-pc-enthusiasts/

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

AMD is really catching up to Intel on all fronts these days:

https://amdflaws.com/

Truga
May 4, 2014
Probation
Can't post for 48 minutes!
Lipstick Apathy
Can't make Intel ME jokes anymore :(

gourdcaptain
Nov 16, 2012

I... aggh... another list of firmware level vulnerabilities.

Computers were a mistake.

Truga
May 4, 2014
Probation
Can't post for 48 minutes!
Lipstick Apathy
open source all the hardware and software

Shy
Mar 20, 2010

Wow that's one hell of a damage control. Okay maybe I'll buy an Intel.

sincx
Jul 13, 2012

furiously masturbating to anime titties
.

sincx fucked around with this message at 05:50 on Mar 23, 2021

repiv
Aug 13, 2009

CTS Labs, a security consultancy, don't even have HTTPS set up on their main site :thunk:

this is fishy as hell

Paul MaudDib
May 3, 2006

TEAM NVIDIA:
FORUM POLICE
This is probably the one time I'm gonna agree that it's a conspiracy. Yeah, Intel probably paid a fly-by-night security firm to do some poking around on AMD processors and see what they could dig up.

it was an NVIDIA false-flag operation

Truga
May 4, 2014
Probation
Can't post for 48 minutes!
Lipstick Apathy

sincx posted:

Intel hitjob?
close
https://twitter.com/cynicalsecurity/status/973599549745979392

HalloKitty
Sep 30, 2005

Adjust the bass and let the Alpine blast

repiv posted:

CTS Labs, a security consultancy, don't even have HTTPS set up on their main site :thunk:

this is fishy as hell

Yeah, there are no contact details, and the whois page is also fishy.
I suspect that this "consultancy" could be some unscrupulous firm thrown a few dollars by Intel.
The page only just appeared, too. There was no record of it before January on the wayback machine in its current state. Before that it was just a landing page.

vv Yeah, that's just frankly comical. I'm all up for hearing about new exploits, but this is just silly

HalloKitty fucked around with this message at 18:22 on Mar 13, 2018

Eletriarnation
Apr 6, 2005

People don't appreciate the substance of things...
objects in space.


Oven Wrangler
I love that one of the exploits requires a BIOS reflash, which for me is beyond even physical access in the realm of "if you can do this, can't you do whatever you want already?"

Anarchist Mae
Nov 5, 2009

by Reene
Lipstick Apathy
Here's a quote from the disclaimer on the website:

quote:

Although we have a good faith belief in our analysis and believe it to be objective and unbiased, you are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports.

Uh huh. Totally not trying to manipulate stock for their own profit.

Cygni
Nov 12, 2005

raring to post

im pretty sure every dipshit hacker on earth has been looking for CPU vulnerabilities after meltdown/spectre got so much press, especially on AMD platforms since they didnt get hit as bad. i highly doubt intel would be dumb enough to get involved in this type of low level trash, but who knows.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

It's really telling that they gave them ONLY 24 hours before public disclosure.

Shy
Mar 20, 2010

I tried to google Viceroy Research and

quote:

We believe AMD is worth $0.00 and will have no choice but to file for Chapter 11
(Bankruptcy) in order to effectively deal with the repercussions of recent discoveries

lmao

gourdcaptain
Nov 16, 2012

I'm going to still go with "computers were a mistake" because now we have to distinguish between the actual crippling security flaws and the hack jobs for financial gain. Such a headache.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA
I read the thing looking for any actual CVEs and the entire thing looks like a hatchet job designed to scare institutional investors away from AMD. Lots of bright, pretty graphics and scary sounding phrases, but no proof of concepts, actual expoits, or anything more than 'if yuo load code in the ring 0 management engine, bad things could happen!!!11!'. Which, to be fair, is true, but also completely retarded to list as an exploit/risk.

feedmegin
Jul 30, 2008

sincx posted:

Intel hitjob?

it doesn't have to be an Intel conspiracy, tbh, it could well just be some random scammers looking to short some stock. Intel's already been hit (by an actual legit thing) so 'AMD have something terrible wrong with them tooooo!' sounds nice and plausible to investors.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Methylethylaldehyde posted:

I read the thing looking for any actual CVEs and the entire thing looks like a hatchet job designed to scare institutional investors away from AMD. Lots of bright, pretty graphics and scary sounding phrases, but no proof of concepts, actual expoits, or anything more than 'if yuo load code in the ring 0 management engine, bad things could happen!!!11!'. Which, to be fair, is true, but also completely retarded to list as an exploit/risk.

Guys my new 0 day just requires physical access to the machine and bios rw. Make the check out to cash plz.

Obsurveyor
Jan 10, 2003

incoherent posted:

Guys my new 0 day just requires physical access to the machine and bios rw. Make the check out to cash plz.

Yeah well all my zero day requires is an administrator login. Just run cellphone.exe as Administrator. Buttcoins only, please.

Paul MaudDib
May 3, 2006

TEAM NVIDIA:
FORUM POLICE
Techpowerup has a decent summary here.

Basically, Ryzenfall and Fallout let you take over the PSP with only a root password (even if this is inside a VM), and from there you can pivot to writing the BIOS (Masterkey) or bypass driver signing and write the chipset drivers (Chimera). So yeah, individually the latter two are not that big a deal, but in combination with the ability to take over the PSP they give persistence.

At least one researcher claims to have access to the POC exploits:

https://twitter.com/dguido/status/973628933034991616
https://twitter.com/dguido/status/973628933034991616
https://twitter.com/dguido/status/973630637012848640
https://twitter.com/dguido/status/973633423851032580

I'm sure there will be patches coming along at some point, and the attempt to manipulate the stock is quite shameless, but they are real vulnerabilities in the PSP firmware.

edit: and he provided commentary for this article: https://motherboard.vice.com/en_us/article/kzpm5x/amd-secure-processor-ryzen-epyc-vulnerabilities-and-backdoors

Paul MaudDib fucked around with this message at 21:23 on Mar 13, 2018

Anime Schoolgirl
Nov 28, 2002

doesn't MSI not even allow you to turn TPM on in Ryzen in the first place?

Kazinsal
Dec 13, 2011




I do not believe the blockchain security researcher in those tweets is involved in any capacity in a 24-hour-disclosure-period massive CPU security bug fest that is in any way real

B-Mac
Apr 21, 2003
I'll never catch "the gay"!
lol nice “office” CTSlabs.

https://m.imgur.com/OkWlIxA

They are all shutterstock images.

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



This feels like that argument a few months ago* over whether it was reasonable for Linux to automatically mount the BIOS as rw but with a ~whitepaper~ and made by opportunistic shitheads I'd like the SEC to ream out with a power drill.

* I'm not sure if it was even in this thread sorry if that's confusing people

WTFBEES
Apr 21, 2005

butt

Disregarding the questionable motives and potentially fake companies in play here, can we all take a moment to recognize how great the name "Ryzenfall" is? Seriously, that's clever.

SwissArmyDruid
Feb 14, 2014

by sebmojo
Only because it rhymes with Titanfall.

PerrineClostermann
Dec 15, 2012

by FactsAreUseless

SwissArmyDruid posted:

Only because it rhymes with Titanfall.

A moment of silence for one of the best games no one played.

B-Mac
Apr 21, 2003
I'll never catch "the gay"!
Just finished titan fall 2 campaign, it was short but pretty drat dope.

SwissArmyDruid
Feb 14, 2014

by sebmojo
Titanfall 2 was mis-publicized so that EA could acquire Respawn on the cheap, I'm afraid to say. Which is a shame, because it was a *great* game. I even played multiplayer of it for a good month or two!

Adbot
ADBOT LOVES YOU

PerrineClostermann
Dec 15, 2012

by FactsAreUseless
It was so much loving fun, with nuanced, skilled movement and an engine that could scale from toasters to the gucci-est of systems. Hell, it even supported 21:9 without breaking a sweat.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply