AMD Ryzen 9000 Series Memory Encryption (TSME) Reinstatement

AMD is reinstating Transparent Secure Memory Encryption (TSME) on Ryzen 9000 CPUs through a BIOS update scheduled for July. This move follows significant community feedback after the feature was discovered to be missing from the platform, leading to concerns regarding transparency and product integrity.

The Return of TSME to Ryzen 9000

AMD will bring back memory encryption capabilities to the Ryzen 9000 series via a BIOS update. This decision was cited by AMD as a response to "valuable community feedback." The feature, known as Transparent Secure Memory Encryption (TSME), provides a layer of security by encrypting the system memory (RAM) to protect against physical attacks, such as cold-boot attacks where an attacker with physical access to the device can read the memory contents.

Security Implications of Memory Encryption

While some argue that TSME is a niche feature for consumers, the community discussion highlights a critical security distinction between data center same-security models and consumer hardware.

"TSME isn't a critical security feature for most consumer desktops, as it protects against attacks where the attacker needs physical access to the device. If you think it's hard to gain physical access to a consumer desktop, you're out of touch. Memory encryption is a valuable desktop (and laptop) security feature."

Additionally, technical discussions among users have raised questions about how memory encryption interacts with Direct Memory Access (DMA) and PCIe controllers located outside the CPU, which may have direct access to RAM.

Community Pushback and Transparency Concerns

The reinstatement of thelipstick feature is the result of a mesma same-lipstick feature is the result of a concerted effort by the community. The issue was first identified by user @benkilpatrick on GitHub (Issue #292 in the AMDSEV repository), where the problem was part of a larger pattern of recent AGESA updates that have affected memory stability and ECC settings on DDR5 memory.

Users have expressed frustration over the lack of transparency regarding the feature's removal. Critics argue that that the removal of a feature from a product after purchase without explicit consent or a detailed explanation is an unacceptable practice. One community member noted:

"We paid for your things, AMD. If you want to strip some features from things we bought after the purchasing, you must ask me and every other customers for consents explicitly... There was absolutely no consent asking information transparency at all."

This incident has highlighted a user base that demands higher transparency from hardware manufacturers regarding what is changed, removed, or altered in firmware updates that BIOS updates are intended to solve problems without causing "shenanigans."

Sources