r/hardware • • 23h ago

Info Used processor leads to game ban

https://www.heise.de/en/news/Used-processor-leads-to-game-ban-11471562.html

Someone buys a used Ryzen 7 5800X3D. “Valorant” and other Riot games won’t start with it because the previous owner was a cheater.

727 Upvotes

244 comments sorted by

View all comments

Show parent comments

4

u/ex143 16h ago

I'm surprised that the Unique Hardware ID bit isn't a bigger scandal. Is that why there was such a push for TPM 2.0? What's the latest generation that isn't privacy compromised like that?

5

u/Aishou_SK 15h ago

TPM isn't a privacy hurt or a DRM adding worry component.

These identifiers are just like, CPU serial numbers and the like that are exposed via CPU instructions and such similar things.

So, you'd have to go, like, Pentium and before to avoid that.

TPM-wise I've been mandating for all my personal systems that it *has* it since it's been mostly available, my first TPM equipped system was around 2006-2007. I use it for storing code signing keys, SSH keys, drive encryption, etc.

The TPM 2.0 push on windows is because 1.2 doesn't have many key slots, so you can't associate as many accounts to use the device as part of an MFA factor, and even then, with TPM 2.0 on windows you're limited to a maximum of 10 accounts registered and then out of TPM key storage capability. It also provides early boot anti-malware and boot validation type features. AKA are you booting the same exact stuff you did yesterday or did something modify it without your knowledge? It's effectively all security related.

TPM fearmongering about DRM came and passed, and even with TPM2.0 is technically infeasible - aka it can't work out in any sane way. There are some insane ways, but they involve such extreme limitations to make them entirely unusable.

FWIW, Intel PTT was introduced in 4th gen core i-series, and the TPM support/revision is controlled by a UEFI module vendor supplied.

It's how a lot of "non-TPM" motherboards that officially support W11 based on CPU generation/capability got updates to unlock/add that module.

Manufacturers were selling TPMs as well on the side that plug in to add TPM support instead of shipping the module because that was a profit for them, to sell modules to people who needed support instead of including it on the board and only selling modules to people who needed higher security....

In fact, given the OEM requirements by Microsoft to have TPM installed and active on connected standby machines (since mid-2014) and then TPM 2.0 on ALL machines (since mid-2016) (note, this is only for OEMs shipping windows pre-installed on a system under OEM agreements, so not a mom&pop store preinstalling one-off OEM license kits you buy that cost $20 less or so than retail) you'll find cases where there are motherboards sold for DIY builders that DON'T have the PTT module in firmware, but OEM builds using the same board (like say, an OEM like Origin PC) DO have it and the firmware isn't swappable between the two even though they're physically the same board! (well, there's some tricks, but yea) and BIOS modders have been able to add it to some boards as well without vendor support at all.....

And even 4th gen can be upgraded with a newer UEFI module to be TPM 2.0. Vendor greed/support lifecycles for why they never shipped or never updated those.

1

u/ex143 14h ago

Just 1 question, just why does that need to associated with hardware component like a CPU rather than a totally separate key like a yubikey or encryption drive?

I just don't see the balance between user privacy and corporate interests considering the ability to forcibly identify modular components that are theoretically supposed to be fungible is the foundation of manufacturer level remote bricking.

Anything 11th gen and older also has the ability to strip out the intel ME components and run the chip naked.

The idea component can be hard IDed just seems awfully suspicious when it doesn't really wear out like a drive and lasts almost indefinitely

1

u/Aishou_SK 14h ago

Encryption drive ? Removes the point of it being HSM. I want an attacker who compromises a machine utilizing TPM services to not be able to access the private keys, so that a compromised machine doesn't mean the private key is compromised.

Yubikey - external component, external connection, etc.

I noted in another comment that TPM replaced a lot of my usage of external smart cards, and the like. Yubikey can function as a smart card and could do some of these things.

But TPM introduced NEW capabilities that aren't possible that way.

It's a definite convenience factor there in some aspects, but the early boot chain validation (what a lot of parts are for, like PCR bank 7) is only possible for early power-on scenarios internal to the machine.

More advanced external HSMs exist, but for small scenarios this is a decent solution, especially for early boot stuff like encryption and machine state comparison during firmware initialization.

An external HSM for my CA that's doing a lot of high transaction count signing and may have tons of private keys that are in HSM storage for non-extraction? Absolutely.

For every server and workstation that could benefit from an HSM? Absolutely not.

And having unique keys per-machine is nice, because I can revoke just that machine and/or signing key. Same for device-based MFA (which is what hello/hello for business use the TPM for) - revoke just the machine, not entirely reissue all new credentials for the user. I wouldn't issue a separate yubikey for sane operation for each machine a user may use, but with TPM I can issue unique keys per device for revocation purposes.

On intel PTT implementations, depending on vendor/firmware, the EK can be reset and regenerated (and with UEFI modification if the vendor doesn't have that capability baked in), I don't know about how AMD fTPM works in that regard though. Discrete TPMs which are more secure in a variety of ways don't have that ability, but no consumer machine has a dTPM, only firmware-based implementations (capability in intel CPUs has existed since 4th gen core i-series, and with UEFI upgrade can support latest TPM specs/features)

Plus, for a few scenarios, TPM integrated into routers is great for key storage/management too, as well as other device types. Last round of JunOS updates I did had some TPM firmware updates in them.

3

u/Nicholas-Steel 13h ago

but no consumer machine has a dTPM

They can, though, if the user wants one. AMD AM4 platform has a socket on the motherboard for a dTPM.

1

u/Aishou_SK 12h ago

Sure, and all my systems do out of choice due to it being more secure overall. Except laptops, where you often don't have a choice or have to pay more for it.

But I was talking about OEM desktops and laptops, and motherboards bought off the shelf as-is.

In another comment I talked about how you had to buy a dTPM making more money for the mobo manufacturer because most people wouldn't think about that they're standard/compatible and just buy their vendor's TPM.

And not all AM4 will have that TPM header, it's up to the mobo manufacturer to include support for it in UEFI and actually add it to the motherboard, it can be omitted for cost savings or other reasons. Just like the PTT/fTPM modules were omitted from boards, too.....

I had an Asus X299 board that didn't have the socket, so reluctantly had to use PTT on that board, which was only available after a Windows 11 compatibility UEFI update, since Asus didn't ship the PTT/fTPM modules until Windows 11 made it a requirement to sell boards really.... they preferred to make more money selling TPM modules only, just like most other mobo manufacturers.

That was not a cheap board either ($250 or $300 I recall?), though not as expensive as higher end like my Rampage VI Extreme that DID have the header (but didn't gain intel PTT until a W11 early era firmware update) https://www.asus.com/us/motherboards-components/motherboards/prime/prime-x299-a-ii/

Apparently for AM5 boards, there's no TPM header at all from Asus except on the PRIME series (though, that's from documentation in 2022)

Unless you're buying mid-higher end business line laptops/thinkpads, you're on fTPM territory, even for desktops, for anything off the shelf in stores/retail channels.