Back
AMD silently drops memory encryption from consumer Ryzen CPUs
SiTech AI Team3 წთ. საკითხავი

AMD silently drops memory encryption from consumer Ryzen CPUs

According to Ars Technica, AMD has quietly removed Transparent Secure Memory Encryption support from consumer Ryzen processors. Users have no way to notice that a protection they enabled in the BIOS is no longer active.

AMD has quietly removed Transparent Secure Memory Encryption (TSME) from its consumer Ryzen processors, according to a report by Ars Technica, leaving owners of those chips unaware that a protection they had enabled in the BIOS may no longer be active.

How the change was discovered

The finding came from Ben Kilpatrick, a self-described privacy-conscious Linux hobbyist, who was installing an operating system on a machine with a Ryzen 7 9700X based on the Zen 5 architecture. Running Host Security ID (HSI), an auditing tool that evaluates firmware and hardware security configuration, he found TSME reported as unsupported even though he had enabled it in the BIOS. He filed a bug report on AMD's public engineering GitHub repository, where AMD engineers Tom Lendacky and Mario Limonciello responded; their advice was to toggle the setting and, failing that, to contact the motherboard vendor.

MSI's tests and an AGESA flag

After Kilpatrick pressed MSI, the board maker's engineers ran controlled tests. Consumer Ryzen chips had TSME enabled under an older firmware version but showed it as "not supported" under AGESA 1.2.7.0, while Pro versions of the CPU supported the feature regardless of firmware or motherboard. MSI's product marketing team was told directly by AMD that TSME is supported exclusively on Pro series processors, and an internal AGESA flag controlling whether TSME activates at boot returned FALSE on consumer chips regardless of the BIOS setting, but TRUE on Pro processors.

The discussion also surfaced a 2020 comment from Lendacky stating that a consumer Ryzen 3700X "should support TSME". Kilpatrick asked whether the FALSE flag was a silicon limitation or a firmware policy decision; Limonciello replied that he had no more information to share on the topic.

What AMD has said, and what is at stake

AMD's only official response, according to the report, is an email stating that TSME "is a security feature only applied to PRO CPUs as part of AMD PRO Technologies" — the first time the company has publicly stated that restriction. It remains unclear whether the change is deliberate product segmentation or a regression introduced in the newer firmware.

Unlike Secure Memory Encryption (SME), which is OS-managed and available only on Pro and EPYC tiers, TSME is firmware-managed and encrypts all RAM without OS involvement, guarding against cold-boot attacks, DRAM interface snooping and memory module removal. The practical impact is narrow but real for users who carry sensitive laptops, handle confidential work, rely on full-disk encryption or face realistic risks of theft or tampering. The removal is undetectable on Windows and requires significant technical work to identify on Linux.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.