this post was submitted on 12 Aug 2024
189 points (96.6% liked)

Selfhosted

38707 readers
677 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

Here we are - 3600 which was still under manufacture 2-3 years ago are not get patched. Shame on you AMD, if it is true.

all 50 comments
sorted by: hot top controversial new old
[–] [email protected] 83 points 1 month ago (3 children)

That's so stupid, also because they have fixes for Zen and Zen 2 based Epyc CPUs available.

Intel vs. AMD isn't "bad guys" vs. "good guys". Either company will take every opportunity to screw their customers over. Sure, "don't buy Intel" holds true for 13th and 14th gen Core CPUs specifically, but other than that it's more of a pick your poison.

[–] [email protected] 26 points 1 month ago (2 children)

Tangent: If we started buying risc-v systems we might get to a point where they can actually compete.

[–] [email protected] 13 points 1 month ago (1 children)

That's still far away from us as a consumer standpoint, but I'm eagerly waiting for a time when I could buy a RISC V laptop with atleast midrange computing capabalities

[–] [email protected] 3 points 1 month ago (1 children)

I‘m more on the builder/tinkerer side so I‘m pretty much in starting position with risc-v now. But yes, its going to be some time before any of it is user ready as a pc.

[–] [email protected] 4 points 1 month ago

Framework has a laptop in progress if you're interested

[–] [email protected] 2 points 1 month ago

Jeff Geerling had a video recently about the state of RISC V for desktop. https://youtu.be/YxtFctEsHy0?si=SUQBiepSeOne8-2u

[–] [email protected] 2 points 1 month ago

“Both sides”

“Vote third party!”

Wtf seriously this isn’t the same thing remotely but the arguments used are.

[–] [email protected] 39 points 1 month ago

Really not good enough from AMD. I wonder if Intel wasn't a complete dumpster fire right now if they would still cut off the fix at Zen 3 (I doubt it). There's really no reason not to issue a fix for these other than they don't want to pay the engineers for the time to do it, and they think it won't cost them any reputational damage.

I hate that every product and company sucks so hard these days.

[–] [email protected] 23 points 1 month ago (1 children)

lol for the past 15 years I have "rebuilt" my desktop every 5 years but I didn't expect the would try to force me out of my 7 3700x right on the date

[–] [email protected] 2 points 1 month ago (1 children)

Which is a shame because our 3700X is still pretty potent for the average user or gamer.

[–] [email protected] 1 points 1 month ago

At launch, I've upgraded my system to a 3900x, and even today, it fulfills my cpu needs. This thing is incredible

[–] [email protected] 15 points 1 month ago (2 children)

How severe is this vulnerability?

[–] [email protected] 34 points 1 month ago (2 children)

The good news is that in order to exploit the new vulnerability, the attacker first has to obtain kernel level access to the system somehow - by exploiting some other vulnerabilities perhaps.

The bad news is once Sinkclose attack is performed, it can be hard to detect and mitigate: it can even survive an OS reinstall.

[–] [email protected] 19 points 1 month ago (2 children)

So basically what you are saying is we just need one pvp game with kernel level anti cheat to fuck up somewhere...... yeah I'm sure that's not going to happen.

[–] [email protected] 5 points 1 month ago (1 children)

Probably only on a targeted attack. I don't see it being a mass target attack like a worm could be.
And in the realm of businesses, how many programs are running in kernel level besides the antivirus/ED(P)R solution?

[–] [email protected] 3 points 1 month ago

And with crowd strike we have seen how reliable Antivirus is.

[–] [email protected] 1 points 1 month ago

we just need one pvp game with kernel level anti cheat

Leaving aside that security patches should be done, if you install that kind of game on a system where you have any data worth protecting, you're a dumb ass mtherfcker. Sorry, but seriously, that's just how it is.

[–] [email protected] 3 points 1 month ago

The other bad news: there are so many vulnerabilities on all systems which can be used to gain root-level access, it's just a matter of time. Also, even future vulnerabilities will be an issue, as the underlying Sinkclose attacks will still work.

[–] [email protected] 9 points 1 month ago (1 children)

You need to be a root to exploit it, but if it get exploited any way to get rid of it is to throw MB to trash.

[–] [email protected] 3 points 1 month ago (1 children)

Patch/reflash with a new bios?

[–] [email protected] 2 points 1 month ago (2 children)

How do you trust that the flash was done properly if you did it from the compromised system? This would only work if you flashed it externally somehow without the system running.

[–] [email protected] 1 points 1 month ago

¯\_(ツ)_/¯

[–] [email protected] 8 points 1 month ago (1 children)

AMD has unfortunately a long history of abandoning products before its reasonable on its graphics division. Its not really acceptable, up until earlier this year my NAS/server was running a 3600 and its only for power saving purposes I changed that as its still a very workable CPU in that role.

[–] [email protected] 2 points 1 month ago

Er I'm still running a FX-8350 as a gaming machine (not AAA games obviously). I had another one as a host for a few VMs and it was more than enough till the motherboard went. One day I'll upgrade I guess.

[–] [email protected] 1 points 1 month ago

The enterprise models are getting patched but the consumer ones aren’t. Shame on them.

[–] [email protected] 1 points 1 month ago

so that means you can internally flash the bios chip from the os?

would be cool if there were coreboot builds for these platforms, this exploit seems pretty useful