Hacker News new | ask | show | jobs
by boring_twenties 2138 days ago
Recent (1-2 years?) AMD BIOS supports disabling the Platform Security Processor (their ME equivalent).

I haven't been able to figure out what exactly this means, but it does seem to be disabled after system initialization. Kind of like Intel's HAP bit, except user-settable.

2 comments

Either like the HAP bit, or less — only disabling its visibility to the OS on the PCIe bus.
Yeah, I'm a little confused as to why they'd bother implementing and deploying this feature without even a cursory explanation of what it does...
Maybe it’s literally classified
I found [1] https://www.igorslab.de/en/inside-amd-bios-what-is-really-hi... to be a good explanation. Essentially it's the crank which brings up the rest of the SOC. The other functions are optional, but no booting possible without it.
Thanks for that! This is quite relevant to me right now as I'm thinking about my next upgrade. Obviously, I'd prefer to buy AMD, especially if this disable switch is legit. But grotesquely, I'm still considering going with Intel, because at least I know I can use me_cleaner there, and more or less understand exactly what it does. Hopefully this document will clear some of that up.