Skip to content

Comment on CVE-2021-26333 - Flaw in AMD PSP chipset affects millions of computersparent

Comments

Ok. I think we are mixing 2 things here. This concrete CVE might not affect Linux. So my question how to install the given drivers is irrelevant.

However, in general all sources I read say that the PSP runs some closed source firmware and it has full access to the main memory. So that will always remain a nasty source of insecurity unless there is a switch to disable it (reportedly some BIOSes have such switch, but I have not heard about any 3rd party audit what such switch does.) Vendors will always tell you that their proprietary solution is secure and does not leak any data until someone can somewhat trustworthy demonstrate that they were wrong. Experience has shown that typically it's not a question of whether it happens, but when it happens. It can take years but someday some smart person finds a way. Some create a logo and a website to earn reputation. others earn money secretly.

No, I don't have any insider information you would not have. I just believe the information that it's an ARM processor running closed firmware and it has memory access.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.