So I had to switch back and I've been on my non overclocked lame motherboard since. But in 2024 I got a cheap laptop for college (I tried to go back again it was a failure that's why I don't count it) and now going all the way back to a few days ago I was interested in trying to overclock this laptop. But this is much more technical. My laptop is a coffee-lake refresh 8th generation i7 processor and also a corporate mass manufactured laptop so it's LOCKED down. Im talking like signed bioses only, intel ME (a whole other bios-adjacent thing that's a major part of the bios stuff) is also signed updates only, updates also straight up prevent rollbacks permanently by changing the encryption. This shit is crazy. So I couldn't change any UEFI variables in the EFI (using a program called RU.efi) shell that were related to cpu stuff because those are also read only after startup. And everything in the CPUs MSR (another another thing heavily related to bios stuff) was almost all read only. But here's the thing. CPU MSRs are volatile. This means they have to be written on boot every time a computer starts up. If there was a way to get it to write my own values then I could unlock a lot more stuff. However there are 2 big issues. 1) this stuff is done by intel ME and intel ME images are verified before being executed 2)I can't even START to figure out what to do about intel ME if the BIOS prevents downgrades by normal means. So I will have to manually flash an older bios image, one that's pre-plundervolt and spectre patches and preferably the first image the manufacturer released. That is IF the image is still "cryptographically" valid although flashing an image involves basically nuking and rewriting the whole chip so unless it's stuff like stored somewhere else which is unlikely, afaik bios chips are the few places that have non volatile data storage. But even when the CPUs microcode is removed from the BIOS image (inte ME section) the cpu will revert to its internal factory microcode which it has permanently burned or "fused" in. So EVEN if I do all that I cannot change what I originally wanted to, which is the turbo ratio multipliers on the cpu. Basically, within the CPU MSR (model service register, it's basically the CPUs built in/bios style config, although it gets rewritten (if verified) during every startup since it's non volatile) there is a section called turbo ratio limits, which defines the max CPU frequency the whole cpu can be at based off of each cores load. For some reason (greed under the guise of power budget limits most likely) intel makes it so the more CPU cores that are at their maximum frequency the less the maximum CPU frequency as a whole can be. So of one core is being used at max speed it can be at let's say 4ghz, if 2 cores it will be 3.9ghz, 3 cores 3.8ghz and 4 cores 3.7ghz. This is the main target that would make overclocking the easiest but it isn't feasibly reachable. It made me sad for a few days because I knew that I knew this last year i just forgot it and did all this research and now feel like a big hubristic dummy. But fuck that, fuck intel anyways im going to do SOMETHING to this corporate hell of an un-tinkerable brick this laptop is even if I can't fucking overclock it. I know that the bios chip itself, the storage that previously mentioned actually only runs at 10mhz which is embarrassingly slow and it turns out the protocol that they use is called SPI. So this has been a "what if I do this?" Game and researching the related information.
If I cannot flash the bios by normal update means I will use the programmer, but I can do better for sure, first let's assume there is some other place that is verifying the image integrity, and let's say the image verification part of the boot process uses a physically different part or takes place at different cpu cycles, that would probably be the easiest way to implement it, after all having the image verification data be the same exact data (like the same physical bit arriving into the cpu at the same time) would probably be a little more expensive then just using a different cycle and yknow, the whole way CPUs work which is separating complex stuff into billions of simple tasks (86-ish of them to be exact), then considering the abysmally slow speed of the bios chip compared to modern electronics in general couldn't I just oh idk, give it the correct data during verification and then slip it my "dirty" image during loading? And apparently yes, I didn't know this but it's called a Time Of Check - Time Of Use (TOCTOU) attack. My idea is that well I have an RPI Pico an 100mhz microcontroller that has tons of gpio pins, considering the bios chip has only like 8 pins, if I were to reverse engineer the bios chip (turns out these things have their own little opcodes in them isn't that cute, I thought it was more like just raw access kinda to a huge array of flash memory, but nope it's its own little 8 bit computer with a giant storage attached ) and then use the superior processing power of the pico to store 2 images, my image and the passing image then I could just give the passing image during verification and my edited image during loading. And the plus to using the raspberry pi pico is that it's fast enough that it itself can be used to do the signal sniffing required to figure out where and if and how the image is being verified (unless it all gets sent once then im kinda screwed and might need something much, much, much faster which there isn't much if anything) so I wouldn't need to do any massive amount of lab work with stuff I don't have nor know how to even start using. But that leads up to the image of the breadboard and the pico yesterday. If I am to eventually, in the medium to far future (I'd give it about 6mo at fast pace and a year or 2 normal pace) emulate a bios chip (there basically all the same chip (same pinout and opcodes)) I need to learn how to communicate with a bios chip in the first place. So I took the bios chip from my "dead" z170 motherboard and I am going to use that to understand how it works. The big plus with this too is that the data sheet is available and really comprehensive for these bios chips and explains everything. Although that day the brain fog issues I was having were crazy I couldn't think like at all it took all day to set up the basic wiring and then figure out how to use the SPI stuff in the pico sdk. And I wanted to do it in C. Issue is I know nothing of C, I only understand the basics of some computer languages like JavaScript(I have a certification from 2020 but I remember fucking absolutely zilch from it) and have a fairly okay understanding of the types of syntax so to speak, how objects and classes work, about 6mo ago I learned how pointers work, I have a bit of knowledge in assembly because I took like 4 lesions in a 40 maybe more lesson online class, so I know what to look up when I don't know something for other languages, and understand somewhat of what im looking at when looking at the documentation. Another issue being is that the pico makes it really easy to communicate with the chips because it has built in SPI stuff in the sdk, but in order to truly understand the chips i will need to switch to something called "bit banging" which is using the raw gpio to communicate by manually coding in the protocol of similar instead of using the simple commands.
Thankfully SPI requires a decent understanding of how it works to even use it in the SDK so once I get more comfortable using the pico (other projects planned) I can switch to bit banging and then emulating the chip.
But motivation is a whole other factor but that's a whole other story
I left out like so much too I can't possibly explain it all let alone coherently
But motivation is a whole other factor but that's a whole other story
I left out like so much too I can't possibly explain it all let alone coherently
Oh also rule of thumb when talking about computer stuff when I say "not possible" oh yes it's possible. Anything is possible, whether it takes 30 years or some crazy exploits (and I mean crazy) there is a way. What I mean by not possible is "not my current path of interest/not currently feasible by me"
I think in eventually I am going to buy an old 386 processor because it's modern enough where the basics of the system is still used (32 bit x86 architecture) and it doesn't have too many pins.
With modern hardware it's entirely possible to make a breakout board for the 386 and it's ram (ram and cpu need to have length matched PCB traces due to really high frequency) because around the 90s CPUs started getting so fast that they switched from static logic to something more transient, meaning that the signals change so fast there is no time to wait for something to physically store so to speak, and basically a cpu that runs in ghz cannot be stopped without loosing all of its data (ways around this but also they have fucking like 900 pins, although most are for power still wayyy too much) but making a breakout board/development board (or buying one probably not making one im not that capable yet) will allow me to study the boot process and understand what's happening on a hardware level during operation. This will give amazing insights into what's happening on the 386s modern 64 bit cousins and give me a very good foundational and operational understanding to be used in future problem solving.
Oh btw it's crazy the 386 came out in 1985 and featured 32 bit architecture I thought 32 bit was mid 90s like what my mental map of modern computing just completely shifted back a decade, I was thinking like that was intel 8088 and ibm 5150 was the mid 80s but like im completely wrong. Although I did previously know that windows 1.0 came out in 1985, by that time that means DOS and similar OSes were no longer in their infancy. But 32 bits? I thought 16 bit was normal until like the mid 90s what
With modern hardware it's entirely possible to make a breakout board for the 386 and it's ram (ram and cpu need to have length matched PCB traces due to really high frequency) because around the 90s CPUs started getting so fast that they switched from static logic to something more transient, meaning that the signals change so fast there is no time to wait for something to physically store so to speak, and basically a cpu that runs in ghz cannot be stopped without loosing all of its data (ways around this but also they have fucking like 900 pins, although most are for power still wayyy too much) but making a breakout board/development board (or buying one probably not making one im not that capable yet) will allow me to study the boot process and understand what's happening on a hardware level during operation. This will give amazing insights into what's happening on the 386s modern 64 bit cousins and give me a very good foundational and operational understanding to be used in future problem solving.
Oh btw it's crazy the 386 came out in 1985 and featured 32 bit architecture I thought 32 bit was mid 90s like what my mental map of modern computing just completely shifted back a decade, I was thinking like that was intel 8088 and ibm 5150 was the mid 80s but like im completely wrong. Although I did previously know that windows 1.0 came out in 1985, by that time that means DOS and similar OSes were no longer in their infancy. But 32 bits? I thought 16 bit was normal until like the mid 90s what
👌1
Ziemniaki
Video
i has been listening this for 10 minutes straight