AMI Archives - The Silicon Underground David L. Farquhar on technology old and new, computer security, and more Fri, 06 Dec 2024 01:59:27 +0000 en-US hourly 1 https://kerosin.digital/rss-chimp16321610 The AMI BIOS breach of 2013 https://dfarq.homeip.net/a-dark-day-for-security/?utm_source=rss&utm_medium=rss&utm_campaign=a-dark-day-for-security Sat, 06 Apr 2013 11:04:44 +0000 https://dfarq.homeip.net/?p=6508 A security professional’s nightmare happened to AMI this week. Tons of confidential data, including the source code for the UEFI BIOS for Intel Ivy Bridge-based systems and an AMI-owned private key for digital signatures, turned up on a wide-open FTP

The post The AMI BIOS breach of 2013 appeared first on The Silicon Underground.

]]>
6508
Friday hodgepodge. https://dfarq.homeip.net/friday-hodgepodge/?utm_source=rss&utm_medium=rss&utm_campaign=friday-hodgepodge https://dfarq.homeip.net/friday-hodgepodge/#comments Fri, 03 Aug 2001 17:33:27 +0000 https://dfarq.homeip.net/?p=675 Now are we going to take viruses seriously? Top-secret Ukranian documents leaked out to the Ukranian press, courtesy of SirCam, including the president's movements during the upcoming independence celebration. An assassin's delight, to be sure.

The post Friday hodgepodge. appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/friday-hodgepodge/feed/ 5 675
04/22/2001 https://dfarq.homeip.net/04222001/?utm_source=rss&utm_medium=rss&utm_campaign=04222001 Sun, 22 Apr 2001 05:00:00 +0000 https://dfarq.homeip.net/?p=792 The times they are a-changin'. I made the pilgrimage to north St. Louis, to visit my church's sister congregation, to see their new PCs. I spotted some Compaq Deskpro EXs at Insight for an insanely low price, and I wanted a respectable name brand, so that was what I had them order. I set one up and let it run, and was surprised to see it came up with a standard AMI BIOS. No more Compaq disk partition-based BIOS? Nope. Not even a Compaq logo. Just an AMI logo, like a clone. The case was a standard microATX case with a Compaq case badge on it. I popped open the case. I couldn't tell for certain if it was an Intel-made board or not (the AMI BIOS suggests yes) but it's a standard microATX board. No weird Compaq drive rails either. Seagate hard drive. The CD-ROM firmware says Compaq. But it's a standard ATAPI CD-ROM. It looks like a Hitachi, but I could be mistaken.

This is good. While the quality may or may not be up to the standards of an oldschool Compaq, in the event of a failure after the warranty period, off-the-shelf parts will work to keep these things running. I can get microATX power supplies and motherboards.

Oh, how do they run? Well, after I cleaned up the root and Windows directories, put in my usual msdos.sys parameters, and replaced emm386.exe with umbpci.sys--they paid for that shadow RAM, so they might as well use it as RAM--the system boots in 20 seconds. That'll slow down after adding the network card and installing more software, of course, but at least we're starting out really strong.

I thought I read in the system specs that they'd have built-in Ethernet, but I may be mistaken. That's fairly easy to remedy. I can pick up a 5-pack of Netgear FA-311s at Mwave for about $70. Two of those will put us in business. I'm disappointed that the FA-310TX, an old favorite of mine, seems to be discontinued; hopefully the 311 uses the same or a similar chipset. In a lab situation I'd prefer Intel or 3Com cards, but the Netgears sell for much less, and I have lots of experience with Netgears in Linux. I've occasionally had problems with Intels and 3Coms in Linux, and since there'll be one or possibly two Linux servers in the lab, and I'd rather start out with standardized parts all around, I'll give Netgear the nod.

Bloatbusters. I believe I mentioned this site before on my old site, but maybe not. These guys look at utilities, tell you what's wrong with them, and sometimes provide a tightly-coded alternative. For instance, here's a Windows CD player. It's 3K in size. Personally, I prefer the play button on the front of my CD-ROM drives, but not every CD-ROM drive has one.

I can't stand their site navigation and layout, but their essays are often entertaining to read.

Along the same lines, there's Radsoft , who plays host to Bloatbusters. Radsoft's product is Extreme Power Tools, a $47 collection of over 100 tightly written utilities, including a 25K file manager that claims to pack in more features than any of Microsoft's file managers. Evidently they used to provide a demo download, but the only demo I can find now contains just their task management tools, which are interesting but certainly not the most generally useful.

The post 04/22/2001 appeared first on The Silicon Underground.

]]>
792
01/26/2001 https://dfarq.homeip.net/01262001/?utm_source=rss&utm_medium=rss&utm_campaign=01262001 Fri, 26 Jan 2001 05:00:00 +0000 https://dfarq.homeip.net/?p=883 Hey hey! It works! The server was down all day yesterday, which was a shame. I wanted to try a new experiment. So I'll try it today.

I saw criticism over at Storage Review on Wednesday morning for their critiques of other hardware sites' reviews. I disagree with this criticism; many of the reviews out there are atrocities, with poor methodology, hearsay, reviewer ignorance, and other shortcomings. Sometimes these reviews are more misleading than the information in the products' advertising or packaging! I believe Storage Review is well within professional bounds to point out these shortcomings when they find them.

The mainstream media does this all the time. Columnists and editors will criticize the reporting done in other publications. Most newspapers also employ one person, known as the ombudsman, whose job it is to criticize and/or defend, as appropriate, the publication's own work.

Seeing as the hardware sites out there often do very sloppy work, even compared to the mainstream media, some policing of it is a very good thing.

Then, over lunch, the idea hit me. Why not do some critiquing myself? I'm trained in editorial writing and editing. I have some experience as a reviewer. And I've published a fair bit of my own work in the arena of technology journalism--newspaper columns, a book, individual magazine articles, a series... So I'm qualified to do it, even though I'm not the biggest name out there. And that kind of content is certainly more useful than the "this is how my day went" stuff I've been posting way too often.

I'm not so arrogant as to assume that the webmasters of these large sites are in my readership and would take my advice. I don't expect to change them directly. What I do expect to do is to raise people's expectations a little. By pointing out what's good and what's not so good, hopefully I can raise the public consciousness a little, and indirectly influence some of these sites. If not, then at least my readers are better informed than they otherwise would be, and that's definitely a good thing.

KT-133A roundup (Tom's Hardware Guide)

This is a roundup of six VIA KT133a boards. Good review overall. It doesn't get bogged down in three pages of history that tend to look like a cut-and-paste job from the last similar review, unlike some sites. But it does give just enough history to give proper perspective, though it would have been nice to have mentioned it took EDO and SDRAM some time to show their advantages as well--DDR is no more a failure than the technologies that came before. Unusual for Tom's, this review isn't obsessed with overclocking either. Lots of useful information, such as the memory modules tested successfully with each board. Inclusion of the DFI AK74-AC, which will never be released, is questionable. I can see including a reference design, but a cancelled commercial board doesn't seem to make much sense. You can get an idea from its scores why it got the axe; it was consistently one of the bottom two boards in the roundup.

Emphasis was on performance, not stability, but Pabst and Schmid noted they had no compatibility or stability problems with these boards. Stability in benchmarks doesn't guarantee stability in the real world, but it's usually a good indication. As tight as the race is between these boards, stability is more important than speed anyway, and since the majority of people don't overclock, the attempt to at at least mention compatibility and stability is refreshing.

Socket 7 Upgrade Advice (AnandTech)

This is a collection of upgrade advice for Socket 7 owners. This review, too, doesn't get too bogged down in history, but the mention of fake cache is noteworthy. This was a PC Chips dirty trick, dating back to 1995 or so, before the K6 series. It wasn't a very common practice and didn't last very long--certainly not as long as the article suggests.

Lots of good upgrade advice, including a short compatibility list and pitfalls you can expect. Also included are some benchmarks, but it would have been nice if they'd included more vintage chips. The oldest chip included was the K6-2/450, and AMD sold plenty of slower chips. You can't extrapolate the performance of a K6-2/300 under the same conditions based on the 450's score.

Also, the rest of the hardware used is hardly vintage--you're not likely to find an IBM 75GXP drive and a GeForce 2 video card in an old Socket 7 system. Using vintage hardware would have given more useful results, plus it would have given the opportunity to show what difference upgrading the video card and/or CPU makes, which no doubt some Socket 7 owners are wondering about. Testing these chips with a GeForce does demonstrate that a more modern architecture will give better peformance--it exposes the weaknesses of the CPU--but indication of how much a new CPU would improve a three-year-old PC would be more useful to most people. Few people have the delusion that a K6-3+ is going to challenge an Athlon or P3. They just want to know the best way to spend their money.

No deceiving graphics or lack of knowledge here; what's in this article is good stuff and well written. It's just too bad the testing didn't more closely resemble the real world, which would have made it infinitely more useful.

Memory Tweaking Guide (Sharky Extreme)

This is a nice introduction to the art of memory tweaking, and it explains all those weird acronyms we hear about all the time but rarely see explained. Good advice on how to tweak, and good advice on how to spend your memory money wisely. They disclosed their testbed and included the disclaimer that your results will vary from theirs--their benchmarks are for examples only. The only real gripe I have is that the benchmark graphs, like all too many on the Web, don't start at zero. From looking at the graph, it would seem that Quake 3 runs six times as fast at 640x480x16 than at 1600x1200x16, when in reality it runs about twice as fast. Graphing this way, as any statistics professor will tell you, is a no-no because it exaggerates the differences way too much.

Asus CUSL2C Review (Trainwrecker)

This is a review of the Asus CUSL2C, an i815-based board intended for the average user. This review has lots of good sources for further information, but unfortunately it also has a little too much hearsay and speculation. Some examples:

"Of course, Asus won't support this [cable] mod and we're pretty sure that doing it will void your warranty." Of course modifying the cable on an Asus product, or any other manufacturer's product, will void your warranty. So will overclocking, which they didn't mention. Overclockers are either unaware or apathetic of this. In matters like this, assertiveness is your friend--it gives a review credibility. One who is assertive and wrong than is more believable than one who is wishy-washy and right.

"Arguably, Asus provides the best BIOS support in the business. We believe Asus develops their BIOS's at their facility in Germany." Indeed, Asus claims to have re-written over half the code in their BIOSes, which is one reason why Asus boards perform well historically. Most motherboard manufacturers make at least minor modifications to the Award, AMI, or Phoenix BIOS when they license it, but Asus generally makes more changes than most. This claim is fairly well known.

I was also disappointed to see a section heading labeled "Windows 2000," which simply consisted of a statement that they didn't have time to test under Windows 2000, followed by lots of hearsay, but at least they included workarounds for the alleged problems. Including hearsay is fine, and some would say even beneficial, as long as you test the claims yourself. This review would have been much more useful if they had delayed the review another day and tested some of the claims they've heard.

There's some good information here, particularly the links to additional resources for this board, but this review is definitely not up to par with the typical reviews on the better-known sites.

DDR Analysis (RealWorldTech)

Good perspective here, in that DDR is an incremental upgrade, just like PC133, PC100, PC66 SDRAM, and EDO DRAM were before it. But I don't like the assertion that faster clock speeds would make DDR stand out. Why not actually test it with higher-speed processors to show how each of the technologies scale? Testing each chipset at least at 1 GHz in addition to 800 MHz would have been nice; you can't get a P3 faster than 1 GHz but testing the Athlon chipsets at 1.2 would add to the enlightenment. Why settle for assertions alone when you can have hard numbers?

Also, the assertion "And don't forget, even though things like DDR, AGP, ATA/100 and other advancements don't amount to a significant gain all on their own, using all of latest technology may add up to a significant gain," is interesting, but it's better if backed up with an example. It's possible to build two otherwise similar systems, one utilizing AGP, ATA-100 and DDR and another utilizing a PCI version of the same video card, a UDMA-33 controller, and PC133 SDRAM, and see the difference. Unfortuantely you can't totally isolate the chipsets, so minor differences in the two motherboards will keep this from being totally scientific, but they'll suffice for demonstrating the trend. Ideally, you'd use two boards from the same manufacturer, using chipsets of like vintage from the same manufacturer. That pretty much limits us to the VIA Apollo Pro series and a Pentium III CPU.

And if you're ambitious, you can test each possible combination of parts. It's a nice theory that the whole may be greater than the sum of the parts, and chances are a lot of people will buy it at face value. Why not test it?

This reminds me of a quote from Don Tapscott, in a Communication World interview from Dec. 1999, where he spelled out a sort of communication pecking order. He said, "If you provide structure to data, you get information. And if you provide context to information, you get knowledge. And if you provide human judgment and trans-historical insights, perhaps we can get wisdom."

This analysis has good human judgment and trans-historical insights. It has context. It has structure. The problem is it doesn't have enough data, and that's what keeps this from being a landmark piece. Built on a stronger foundation, this had the potential to be quoted for years to come.

The post 01/26/2001 appeared first on The Silicon Underground.

]]>
883
12/23/2000 https://dfarq.homeip.net/12232000/?utm_source=rss&utm_medium=rss&utm_campaign=12232000 Sat, 23 Dec 2000 05:00:00 +0000 https://dfarq.homeip.net/?p=914 The presidency again. The story that won't die. I thought it was over! When will it end? This is the most ridiculous recount story I've heard yet.

New adventures in Linux. I was trying last night to make a Linux gateway out of a single-floppy distribution for the first time. I looked at a number of distributions and finally settled on floppyfw. Why that one in particular, I never decided completely.

Gatermann and I put a minimalist system together: a vintage 1994 Socket 5 Pentium mobo, a P75, 24 MB of 72-pin SIMMs, a floppy drive, a 2 MB PCI Trident video card, and two Bay Netgear 310TX NICs in a beat-up case. Neither of us normally names our computers, but looking at it, we decided this computer's name was most definitely going to be Mir.

It booted up and seemed to detect the two cards, most of the time. Once it told me eth0 was sitting at IRQ 149 and had a MAC address of FF FF FF FF FF FF, which disturbed me greatly for obvious reasons. Fortunately, this board's AMI BIOS allows you to manually assign resources to the PCI slots, so I went in and did that: PCI slot #1 got IRQ 9, up through PCI slot #4, which got IRQ 12. That gave me some consistency, but I never did get it to successfully ping any address except 127.0.0.1, the loopback address.

We may be dealing with a hardware problem. We'll tackle it again soon, possibly with a more complete distribution. I have no shortage of small hard drives. I also have no shortage of other parts.

These projects never go smoothly but I always get them running eventually.

Picking a single-floppy distribution. The big thing is finding one that supports the hardware you have. There's not enough room on a floppy disk to support every kitchen sink and hairdryer that you might want to use in a Linux box, so any old distribution might not work with your hardware. When Steve DeLassus and I were making a gateway out of his 486SX, we couldn't find any distribution that didn't require a math coprocessor, for instance. (There are some now.) If you're using NICs based on the DEC Tulip chipset or NE2000 clones, you shouldn't have any trouble, but if you've got exotic NICs, not every distribution will support them.

Plus, some of these projects have to be built under Linux. Gatermann doesn't have a working Linux box at the moment. Others build on any old PC running DOS or Windows. Each distro has its own specialty, so you just have to find one that matches your hardware.

This search over at Freshmeat can give you a headstart if you're interested in this kind of thing.

The post 12/23/2000 appeared first on The Silicon Underground.

]]>
914
Identifying the motherboard in a mystery system https://dfarq.homeip.net/identifying-the-motherboard-in-a-mystery-system/?utm_source=rss&utm_medium=rss&utm_campaign=identifying-the-motherboard-in-a-mystery-system https://dfarq.homeip.net/identifying-the-motherboard-in-a-mystery-system/#comments Wed, 26 Apr 2000 16:24:15 +0000 https://dfarq.homeip.net/?p=962 Wednesday, 4/26/00

The post Identifying the motherboard in a mystery system appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/identifying-the-motherboard-in-a-mystery-system/feed/ 1 962
Refurbishing a Pentium-75 https://dfarq.homeip.net/refurbishing-a-pentium-75/?utm_source=rss&utm_medium=rss&utm_campaign=refurbishing-a-pentium-75 https://dfarq.homeip.net/refurbishing-a-pentium-75/#comments Tue, 04 Apr 2000 19:14:02 +0000 https://dfarq.homeip.net/?p=1186 Remember that Pentium-75 I worked on a couple weeks ago? It's back. I love problem-child PCs. Not. But its owner couldn't be nicer about it, so that makes it better to deal with. This time I'm doing what I should have done in the first place: clean reinstalling Win95 with a minimalist setup. It works so much better that way.

The post Refurbishing a Pentium-75 appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/refurbishing-a-pentium-75/feed/ 7 1186