• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

AMD video drivers make your computer less secure.

PRIME1

2[H]4U
Joined
Feb 4, 2004
Messages
3,942
Reading many of the posts on this forum I feel confident to say that the biggest security risk is the users themselves.
 
No windows computer running windows is secure either.

Microsoft released an emergency Windows update on Sunday after revealing that one of its trusted digital signatures was being abused to certify the validity of the Flame malware that has infected computers in Iran and other Middle Eastern Countries.

I am sure this is not the first time or last time something like that will happen.
 
1. The AMD drivers do not "disable" this feature, it is disabled by default in Windows because some applications will crash.
2. Any application that wants to can still use it, you just can't force all applications to use it at the OS level you need to leave it up to them:

"Why is this functionality not exposed by default? Some software is not compatible with ASLR and may not function properly as the result of enabling it or other EMET mitigations. "

In other words, even if AMD's drivers supported ASLR you could still cause mystery crashes in programs by forcing it on at the OS level.
http://forums.anandtech.com/showpost.php?p=33544273&postcount=6

http://support.microsoft.com/kb/2458544
"Are there any risks to using EMET?
The security mitigation technologies that EMET uses carry an application compatibility risk with them. Some applications rely on exactly the behavior that the mitigations block. It is important to thoroughly test EMET on all target computers by using test scenarios before you deploy EMET in a production environment. If you encounter a problem with a specific mitigation, you can individually enable and disable the specific mitigations. For more information, refer to the user's guide that is installed with EMET. "

http://support.microsoft.com/kb/2458544
"ISV Tasks
ISVs should link with Microsoft Linker version 8.00.50727.161 (the first version to support ASLR) or later.
ISVs should link with the /DYNAMICBASE linker switch, unless using Microsoft Linker version 10.0 or later which enables /DYNAMICBASE by default.
ISVs should test their application on Windows Vista and later and note and fix failures due to ASLR."


Edit: certainly AMD should make their drivers ASLR-safe, but flipping the switch to make all programs use DEP and ASLR may still result in programs crashing. If it was 100% safe, MS would have changed the default setting to ON in Vista or 7.
http://forums.anandtech.com/showpost.php?p=33544407&postcount=8
 

Yeah it seems this security feature has been around since Vista and as noted in your post

ISVs should test their application on Windows Vista and later and note and fix failures due to ASLR."

Essentially you can not run a highly secure system with AMD drivers installed. Hopefully they fix this quickly. Although it seems they have been aware of this problem for awhile.
 
I know I should read the link, but im sick of wasting time going to Prime1's links only to be dissapointed in the BS.
 
Yeah it seems this security feature has been around since Vista and as noted in your post



Essentially you can not run a highly secure system with AMD drivers installed. Hopefully they fix this quickly. Although it seems they have been aware of this problem for awhile.

Talking toss, and don't try to re-interoperate the facts when in order everything installed and run must have that feature which they do not, AMD drivers having it changes nothing in a consumer PC environment as the feature is off and other sw don't support it, a custom secure system with bespoke software is another matter .

Yes they should still fix it, but its little more than crying about having a 75m rope over a 100m rope when you need 200m to reach the other side.
 
This isn't really relevant to consumer PCs that people are using at home to play games, but it is something they should fix, and it looks bad on AMD and the driver team.
 
Back
Top