AMD has quietly stripped a critical security feature from its mainstream processors, exposing users to the risk of data theft if a malicious actor gains physical access to their machine, according to a recent Ars Technica investigation.
The omission was uncovered by long‑time GitHub researcher Ben Kilpatrick, who confirmed that the memory‑encryption tool—once a staple of AMD’s hardware—has disappeared from the consumer lineup.
Known as TSME, this protection encrypts all data residing in a system’s RAM, rendering it unreadable if an attacker can tamper with the hardware. Initially reserved for high‑end chips, the feature eventually rolled out to budget models, operating flawlessly for years before AMD decided to remove it without warning.
Kilpatrick, a privacy‑focused Linux enthusiast, stumbled upon the flaw while installing a fresh OS on his Ryzen 7 9700X system. He discovered that the encryption was disabled even though he had enabled it in the BIOS, a change that would go unnoticed on Windows platforms.
Undeterred, the user reached out to MSI, where the company’s engineers conducted controlled tests. Their findings revealed that the security function was indeed active in older BIOS versions but became disabled after installing the latest motherboard update, AGESA 1.2.7.0. Interestingly, the professional-grade processors retained the feature regardless of the update, leaving the industry to wonder whether the removal on consumer chips was an inadvertent oversight or a deliberate, unannounced market strategy.
Armed with this evidence, the user reopened the public forum to confront AMD’s engineers directly. He reminded Lendacky of a 2020 statement asserting that the security system operated flawlessly on consumer CPUs, demanding clarification on whether the current issue was a permanent limitation or a reversible decision. Limonciello abruptly ended the exchange, admitting he had no further information to share.
AMD’s sole official response outside of these discussions came in the form of an email, declaring that the protection is exclusive to its PRO technology—a first public acknowledgment of this restriction after years of the feature being available on consumer devices. Unlike other security measures that require manual OS configuration, the TSME automatically encrypts all memory from power‑on, safeguarding systems against RAM extraction or direct data theft—an essential safeguard for high‑risk environments.
While the quiet update may only marginally affect most users, it poses a significant security risk for anyone operating laptops that store sensitive information—data that could be compromised if memory encryption is lost. Until AMD provides a formal clarification or restores the missing support, those who need genuine memory protection will be compelled to invest in pricey enterprise-grade solutions such as Ryzen Pro or EPYC systems to safeguard their data.
❓ Frequently Asked Questions (FAQ)
What is TSME and why is its removal concerning?
TSME (Trusted System Memory Encryption) is a hardware feature that encrypts all data in a computer's RAM, making it unreadable to anyone who gains physical access to the machine. AMD’s decision to remove this feature from mainstream processors without notice means that many users who previously relied on built‑in encryption are now exposed to the risk of data theft if their hardware is compromised.
How does the removal of TSME affect my PC’s security?
Without TSME, data stored in RAM is no longer automatically encrypted. If an attacker can physically tamper with your system—such as by installing a memory‑reading device or extracting RAM modules—the contents of your memory could be captured and read. This increases the attack surface for hardware‑based attacks, especially on laptops, workstations, and gaming rigs that may be left unattended.
What can users do to protect themselves now that TSME is gone?
Users can mitigate the risk by enabling full‑disk encryption (e.g., BitLocker, VeraCrypt) to protect data at rest, using secure boot and TPM to safeguard firmware, and keeping BIOS/UEFI firmware up to date. For sensitive environments, consider third‑party hardware encryption solutions or moving to processors that still include TSME. Additionally, physically securing devices and monitoring for unauthorized access remains essential.
News Source: Tarreo
Comments
Be the first to comment.