
Episode notes
AMD silently removed a memory-encryption feature from its consumer Ryzen chips in a firmware update earlier this year. Users noticed. Users complained. Over the weekend, AMD said it would put the feature back in a July BIOS release. Dan Goodin covered the reversal at Ars Technica. The feature is called TSME — Transparent Secure Memory Encryption — and it has been shipping in consumer chips for about a decade. AMD did not explain why the feature was removed. AMD did not respond to questions about the reversal either.
The removal was undetectable on Windows and required significant technical work to detect on Linux. The mechanism was a firmware update — AGESA 1.2.7.0 — distributed through the AMD-to-OEMs-to-end-users chain, with no mandatory public changelog requirement for security-relevant changes. The same silicon was capable of TSME before the update and after; what changed was the firmware's willingness to enable it. AMD's Pro version of the chip retains the feature under the Memory Guard branding. The consumer version had it for ten years. The consumer version no longer has it. The consumer version will have it again in July. The decision-making mechanism that produced the removal is intact and unaccounted for.
The editorial center is the gap between what was removed and what was demonstrated. The feature itself is narrow — cold-boot attacks require physical access, a window of seconds-to-minutes after power loss, and equipment to read DRAM contents before the bits decay. For most consumer Ryzen buyers, the realistic adversary pool is small. The feature matters for a specific population: journalists, dissidents, executives traveling to adversarial jurisdictions, anyone whose threat model includes border crossings. The decision-making process that produced the removal is not narrow. AMD shipped a security capability for ten years, removed it silently through firmware, declined to explain, and made the removal undetectable on Windows. That sequence tells you what AMD thinks about customer trust and how AMD makes decisions about security features. The Fortune 500 procurement officer reads Ars and thinks about pointed questions for their AMD account team. The EPYC customer reads Ars and adds a line to the staging-cycle diff checklist. The move is forty years old — IBM ran it on mainframe microcode in 1986, Sun ran it on Solaris patches in the late nineties, Oracle still runs it on CPU licensing. The mechanism changes. The move is the same. The reversal here is local. The mechanism is permanent.
Source Article
Following user outcry, AMD reinstates memory encryption in consumer CPUs — Dan Goodin, Ars Technica, June 22, 2026.
Panel
- The Legacy Sysadmin
- The Paranoid CISO
- The DBA
- The Goat Farmer's Counsel
