惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Hackread – Cybersecurity News, Data Breaches, AI and More
U
Unit 42
Vercel News
Vercel News
Martin Fowler
Martin Fowler
云风的 BLOG
云风的 BLOG
爱范儿
爱范儿
MongoDB | Blog
MongoDB | Blog
J
Java Code Geeks
F
Fortinet All Blogs
MyScale Blog
MyScale Blog
C
Check Point Blog
N
Netflix TechBlog - Medium
Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
博客园_首页
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
Last Week in AI
Last Week in AI
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
Jina AI
Jina AI
V
Visual Studio Blog
小众软件
小众软件

TechSpot

Flagship Rematch: Ryzen 7 5800X3D vs. Core i9-12900K Slack chats and internal data from failed startups are finding a second life in AI training A $5 Bluetooth tracker hidden in a postcard exposed a warship's movements Leakers claim PlayStation 6 could offer at least 3x the performance of the PS5 The Mac Mini is no longer a niche product, it's local AI infrastructure IPv6 traffic reaches parity with IPv4 for the first time, Google data shows Xbox expansion cards are now cheaper than SSDs, and PC users are repurposing them Blue Origin prepares to reuse New Glenn booster in bid to challenge SpaceX Nvidia could bring back the 12GB RTX 3060 as supply issues disrupt GPU roadmap What was the first OS you ever used? SNK revives NeoGeo AES with modern upgrades and HDMI support Valve's Proton 11 beta boosts Linux gaming with better performance and classic game support Researchers warn Microsoft Defender vulnerability is already being exploited A four-day Steam freebie turned into $250,000 for an indie game AMD may relaunch Ryzen 7 5800X3D for AM4's 10th anniversary This humanoid robot can almost run as fast as a human sprinter Two New Jersey men jailed for helping North Korean IT workers infiltrate 100+ companies A $7,000 DIY radar project is taking on hardware that usually costs over $100,000 Metro 2039 is going darker than ever, launching this winter on PC and consoles Gemini arrives on macOS with a dedicated desktop app AI infrastructure boom pushes AMD, Intel and Arm to new valuation heights New self-healing material can repair itself over 1,000 times, extend the lifespan of cars and aircraft Japan's bullet train to debut high-tech private cabins, for an added fee Memory card and flash drive pricing surges 120%, with some models spiking 260% Open-source tool decrypts all private data collected by Windows Recall on Copilot PCs The 2026 PC and Console Gaming Report shows most revenue now comes from games outside the Top 20 PureMac is a new open-source macOS cleanup and app removal tool Your Airbnb host might actually be AI Steam might soon display 30-day price history for game deals Intel brings 18A process to budget laptops with new Core Series 3 CPUs
AMD quietly disabled RAM encryption on some consumer Ryze...
Skye Jacobs · 2026-06-17 · via TechSpot

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

TL;DR: About a decade ago, AMD added Transparent Secure Memory Encryption to its high-end processors to close a gap in hardware security. TSME encrypts everything in RAM, which blunts cold-boot attacks and other hands-on memory exploits targeting data as it sits on the DIMMs. Over time, the same mechanism quietly appeared on some consumer Ryzen chips as well. Then, after a recent firmware update, it stopped working there, and AMD has offered only a limited explanation for why.

The change came to light in April, when Ben Kilpatrick installed a new OS on a Ryzen 7 9700X system built on AMD's Zen 5 architecture. He describes himself as a "privacy-conscious Linux hobbyist," and part of his routine is to verify that hardware security features are switched on. To do that, he uses Host Security ID, a checker that inspects firmware and hardware configuration.

On earlier firmware, HSI had reported that RAM encryption was enabled on his machine. This time, the readout showed "encrypted RAM: not supported," even though TSME was still enabled in the BIOS.

A few lines lower, HSI showed that the same system had previously reported RAM as "encrypted." The mismatch between the BIOS setting and the current status is what prompted him to look for an explanation.

Kilpatrick contacted MSI, which made his motherboard, and pushed for tests across different boards and firmware versions. MSI engineers eventually confirmed that consumer Ryzen CPUs reported TSME as supported when an older version of AGESA, AMD's Generic Encapsulated Software Architecture, handled the firmware path during boot.

When systems booted with AGESA 1.2.7.0, those same chips reported TSME as "not supported." Pro-branded Ryzen parts did not change behavior. They showed TSME support across both MSI and Gigabyte boards and across AGESA revisions.

That pattern suggested the silicon was still capable of TSME and that the shift in behavior was tied to firmware. "The big outstanding question is whether this is a deliberate policy decision by AMD to restrict TSME to PRO chips, or an unintentional regression that was introduced in AGESA 1.2.7.0," Kilpatrick told Ars Technica. In his view, "either way the silicon is capable, either way the change happened in AGESA, and either way AMD has declined to explain it."

To get a more direct answer, he opened a bug report in AMD's public GitHub repository for its secure virtualization and memory features. Two AMD engineers responded. Tom Lendacky, an AMD fellow software engineer, said he did not know what caused the change and suggested toggling the BIOS setting: turn TSME off, then back on, and if that failed "my guess would be that it is a BIOS issue and you would want to contact MSI."

Mario Limonciello, a senior principal software engineer who maintains the fwupd implementation of HSI, gave similar advice: try again at the BIOS level, and if it still doesn't work, "then yes please report it to your board vendor to debug."

By the time Kilpatrick returned to the thread six weeks later, MSI had done more detailed analysis. He reported that MSI's product marketing team told him "that AMD officially communicated to MSI that TSME is exclusively supported on PRO series processors."

MSI engineers also broadened their tests. On an Asus X870E board, a Ryzen 9800X3D and a Ryzen 9945 were swapped in and out with the same BIOS configuration. With the Pro chip installed, the system reported tsme_status = 1. With the consumer chip, it reported tsme_status = 0.

The team then examined how AGESA made decisions early in the boot sequence. They captured the output of the AMD Boot Loader, a component within AGESA that runs before the OS, and compared internal state.

One flag, DfIsTsmeEnabled, determines whether TSME is actually turned on during firmware initialization. In the dumps MSI provided, DfIsTsmeEnabled returned FALSE for the Ryzen 9800X3D even when the BIOS had TSME set to AUTO or ENABLED. On the Ryzen 9945 and on Epyc parts, the same flag returned TRUE when TSME was enabled.

Kilpatrick pointed the engineers back to earlier commentary from AMD that showed a different stance. In a 2020 discussion about encryption support in AMD CPUs, Lendacky had written that a consumer-grade Ryzen 3700X "should support TSME," and later added, "I recommend using TSME (Transparent SME), but it is a BIOS option that needs to be exposed by your BIOS provider."

That history, combined with the years where TSME behaved as expected on some non-Pro chips, is part of why Kilpatrick and other users viewed it as a standard part of the package.

After presenting the new AGESA and ABL data, Kilpatrick put a precise question to the engineers: "is DfIsTsmeEnabled being set to FALSE on consumer SKUs a silicon-level limitation, or is it a firmware policy decision within AGESA? The distinction matters quite a bit from a user perspective, since one is fixed and the other is potentially changeable."

Limonciello replied, "My apologies; but I don't have any more information to share on this topic." AMD, responding separately by email, said that TSME "is a security feature only applied to PRO CPUs as part of AMD PRO Technologies."

AMD has long drawn a line between TSME and Secure Memory Encryption. SME, which the company has always described as limited to Pro and Epyc tiers, is managed by the operating system and can encrypt selected memory pages using a single key. TSME is managed in firmware and encrypts all RAM without any involvement from the OS. When enabled in BIOS, it operates silently but still protects against cold boot, DRAM bus snooping, and similar physical attacks.

For users who had built threat models around that behavior, the quiet removal of TSME from newer consumer-grade processors, combined with the absence of a detailed technical rationale, has been unsettling.

Joe FitzPatrick, who focuses on silicon-level security, argued that the lack of clarity is the main problem. "They could have not realized they did it leading to their cagey responses, or they could have done it intentionally and tried to get away with it, leading to the same cagey responses," he said. "But I really feel like an explanation should be in order, even if it was 'TSME was never supposed to be supported. We did ship some firmwares that erroneously enabled it, but you shouldn't use them since we can't guarantee it'll work properly.'"