• 10 Posts
  • 29 Comments
Joined 11 months ago
cake
Cake day: September 29th, 2025

help-circle

  • They are microprocessors embedded within the microprocessor. Intel’s IME enables remote access (by intel’s own admission). If you are not a corporation who manages a fleet of machines, the backdoor can only be used against you. AMD’s variant called the PSP is similar but closed-source. We don’t really have a complete picture of the extent of the compromise with AMD because of the opacity of it (as AMD proactively denied a request for source code). What we don’t know /can/ hurt us, as we already got stung by a defective driver for the AMD’s PSP.

    Even if the spychips were to be hypothetically designed to be aligned with the interests of non-corporate individual consumers, there is no such thing as bug-free software. They have added complexity that works against us and brings vulnerabilities. And we also cannot dispense of the deliberate design whereby some remote actor decides for the user what software is or is not “authorised” to execute. I alone should decide what is authorised on my PC.

    So the fix is to use an AMD processor made before ~2014 (roughly speaking), or a pre-2009 intel. AMD chips were behind intel in terms of performance, but probably not 5 years behind. So I figure 2013 AMDs are the most interesting. But we only have a fuzzy idea of which AMD chips are spychip-free.


  • What I would expect to happen is when an AOS or iOS device falls in your range in the future, it will not report the AP to the mothership. But the motherships will still remember the history and perhaps be able to continue exploiting it. To have more certainty, I would change the MAC address on the AP if it lets you, and perhaps also change the prefix of the SSID for good measure. If your AP gives no means for changing the MAC, you could investigate replacing the firmware with openwrt – but probably not worth the effort just to change the MAC.

    When I setup an AP, I chose the same SSID as a neighbor but then added the suffix for fun… to confuse things. Then they changed their SSID (perhaps in fear that something dodgy was going on).








  • I appreciate the link. I wanted to see what you saw, so I opened the ZIP file and it expands to 27 files. I believe the relevant file is USB_PD_R3.2_V1.2_2026_05_20.pdf, page 42, which states:

    3.2.5.2. SPR Programmable Power Supply (PPS) Programmable Power Supply (PPS) is Optional. When included, the voltages and currents a PPS Shall support are as defined in Table 3.4.

    If it’s optional in rev. 3.2, I assume it’s optional in rev 3.0. I’m a bit astonished because PPS is probably the most signficant feature of rev.3. The industry is not competent enough to even tell consumers which rev a device conforms to. But if it did, typical Wikipedia-informed consumers who see PD “rev.3” advertised would naturally expect PPS. As you are correct that PPS is indeed optional, many consumers will get burnt by the misunderstanding.

    A potentially interesting follow-up question would be whether the laptop’s mainboard PDO tells you the laptop supports PPS even though its power brick doesn’t.

    What’s PDO?

    The problem seems to be that a laptop could be designed to /need/ PPS, e.g. if the voltage it needs is well below 20v. While most PSUs do not advertise USB-PD 3(+) compliance, much less PPS.


  • So anyone not following the tech chatter, here is a TL;DR Cliff’s notes of the scenario…

    Imagine Howard on Big Bang Theory Howard on Big Bang Theory

    is in the shop buying a robot. Conversation goes like this:

    Howard: will the Dell robot give me a hand job?
    Sales person: I have no idea… cannot guarantee anything about that. Nothing in the specs says that it can do that.
    Howard (to the Dell robot): do you have a program to give hand jobs?
    robot: yes I offer services to the PD (Personal Delight) specification.
    Howard: I’ll take it!
    …(at home after naming the robot “Della”)…
    Howard: Della, give me a hand job.
    Della: no, I cannot execute the handJob() program. My hand is only spec’d to grab objects using 40 newtons of clamping force. My programming does not support a variety of levels of force in small steps. Objects I grab also must meet a minimum size constraint.
    …(back in the shop)…
    Howard: I would like to return this Dell product. It refused to execute my command.
    Sales person: Sorry Howard, I told you I did not know if the robot had the capability to inquired about. There are no returns.

    In short, it’s a problem where the sales info and literature does not lie, but the machine can itself lie about its own capability.



  • Counter question: where does it say on there that it’s PD3.0?

    Nowhere. I found no mention of PD anything which inspires some of my questions.

    Perhaps it follows since stuff from the PD3 specs and that’s why that tester said it, but this is guesswork.

    That’s indeed the sort of answer I was looking for. The testing device detects PD3. This somewhat suggests that electronically the PSU (falsely) identifies itself as PD 3.0-compliant.

    Perhaps I’m misunderstanding you but the gist of your text is “why is this item not saying what a random guy said it should say??”

    I want to understand the contradiction. The testing device declares that the PSU is PD3. But the test results led the blogger to claim it’s not PPS. So where is the lying occuring? I expect the PD protocols to establish a handshake whereby each side of the handshake discloses the PD revision it adheres to. Otherwise the protocol is quite shitty.

    If we assume a non-shitty protocol, than the Dell PSU is falsely announcing itself as PD3 and the tester is just a messenger.

    Edit: remember that companies need to pay fees when they advertise with the standard - they can just follow its spec without advertising it at all, I can see that happening for laptop producers specially as they don’t sell their power units as generic products (i.e. with a focus to market them).

    That’s interesting. I suppose the fees finance a certification effort. And I suppose that’s fair enough. But if a device claims to be PD3 not on the label but makes this claim in the electronic protocol, the claim is still a claim nonetheless. People and machines rely on claims made by protocols. And I suppose it’s all legally dicey. Dell could not be easily prosecuted for false advertising if they wrote nothing on the box or label that a buyer would see. But the hardware is still lying about its capability and I would think that would (or should) have consequences.

    legal liability?

    Dell’s ass might be covered as well if these PSUs are sold only with the appliance they drive, and the docs say to only ever use X with Y, do not sell separately, yada yada. Dell knows that most consumers just look for the USB-C connector and are happy enough if they see it.

    But is Dell safe? What if someone attaches this Dell PSU to a 17.5v appliance. The appliance is told by Dell’s handshake that it’s PD3-compliant. So the appliance starts the negotiation at 20v and tries to use PPS to get the voltage down to 17.5. But because the Dell PSU lied, it sticks with 20v and fries the appliance. Is that possible?

    what happens at the street market

    The reality is that the laptops get separated from the chargers. At my local street market, laptops almost never come with a charger. Then some other people are only selling chargers and no laptops. Chargers were fished out of dumpsters, often. Of course it’s an ecocidal defeat of the purpose of USB PD to a large extent if Dell’s business model flies… if they can still say their Dell charger is only for Dell laptops, then it’s basically e-waste when separated from the laptop.

    Dell buyers should pay attention to whether new laptops are advertised as using USB PD. Because if so, then it’s a deception that the laptop includes a charger that is not. Or is left for Dell owners to guess that their laptop depends on a USB PD PSU?

    Can sophisticated consumers get stung by this?

    An advanced consumer would show up to the street market with a test rig that feeds PSUs from an inverter. They would quickly see “PD3” on their fancy test tool and conclude the PSU is worth buying. Only to later find after deeper tests that it’s not actually PD3. Because the PSU lies in the handshake.

    Yet another element of the USB-PD shit show

    When OEM PSUs are sold on the 2nd-hand market with a list of output voltages and a USB-C connector, buyers are obviously going to expect the PSUs to drive their USB-PD appliance. It does not say on the label of that Dell PSU “only for Dell laptops, not USB PD compliant”. But by arbitrary chance, the PSU will happen to work for some non-Dell appliances. But we cannot count it. We can only guess. It’s indeed a fucking shit show.



  • Oh, so to be clear, an asus laptop that expects a USB PD supply can still detect whether or not it’s an OEM charger? And when it’s non-asus, it distrusts the capability and only draws 65w even if the PSU can do 100w?

    IIUC, that’s a bit fucked up. I’ve read claims that either USB PD or the proprietary 3-pin predecessors are supposed to be smart enough so appliances can go easy on PSUs that are not up to the full load, but I was expecting USB PD to not have vendor favoritism problems like that. I appreciate the tip. Seems like another gotcha that can even burn above average consumers who know to a reasonable extent what they are doing.

    (update) found this

    Myth #2: “Original Chargers Are Always Best” Truth: Not anymore.

    Many manufacturers use cheap chargers to cut costs. A quality USB PD charger often beats what’s in the box.

    So I have to wonder if an asus laptop would actually nanny a non-asus PSU that is better than the asus oem psu.


  • You’re misreading the blog post. That adapter has 19.5V written on it, but it requests 20V. 19.5V is not a PD voltage.

    We know the /result/ is 20v, not what was requested. It’s a lie and abuse to print 19.5v on an adaptor that is actually just requesting 20v. It’s certainly /possible/ that is what is happening, which obviously proves my point nonetheless. It’s yet another demonstration of the USB PD shitshow. Either way in fact. Whether the negotiation is a lie, or whether the source is saying “close enough, will send 20v”, it’s a shitshow either way.

    But now it’s worse because consumers who know how to pay attention to voltage are getting a product that’s not delivering what they signed up for.

    Worth noting that the PPS spec of the PD3 standard allows for 20mV step adjustments to the fixed voltages. If the 19.5v adapter is not lying, it’s trying to down-step the 20v (which will only work if the source PSU is PD3 or higher). And indeed the author’s PSU supports PPS. Yet despite that, consumers are still not getting what they believe they signed up for.

    The latter is pretty much impossible to make to spec, because it can’t negotiate voltage. A barrel jack is single-voltage by necessity.

    First of all, the adapters exist. Not impossible. If you meant to say a smart negotiating one is impossible, I don’t believe that either. It could detect whatever the barrel passes and use that result to negotiate only for that available voltage. It could even have a voltage converter that supplies voltages that differ from the source. In fact I have a DC-DC adaptor. You probably have one and don’t know it. A USB charger that plugs into a car’s cigarette lighter converts 12v to 5v. I have one that has a variety of tips and a range of voltages. Detecting the source voltage may not be cheap, but not impossible. It would also be possible to have a cheap manual switch to specify input voltage.

    Respectfully, I’m going to have to disagree. It’s much more interesting when it catches fire, and I’d rather have a protocol that sometimes doesn’t operate in order to avoid the excitement of one that sometimes explodes

    If you find explosions interesting, you can go play with fireworks or watch war movies. It’s not academically interesting that tech illiterate consumers find countless ways to shoot themselves in the foot. When engineers — who /should/ know what they are doing, push a shitty standard that burns even consumers who have the basic knowledge to match devices, that’s academically interesting because it’s people we expect to be smart fucking up. When a whole industry fucks up, that’s academically interesting. I cannot charge a 5v bicycle light using a USB PD spec’d PSU because the industry fucked up on the meaning of “default”.

    No matter what charging standard you use, some idiot could cut off the end, wire it to a stun gun, and send 100,000V into your phone. That doesn’t make the standard bad, it makes the adapter bad.

    Dumb consumers are not in short supply. It used to be that only tech-illiterate consumers were getting burnt. Which created an incentive for consumers to gain knowledge. The nannying attempt at a remedy has enabled informed consumers to get burnt. At the same time, it dumbs down society. When expert consumers can get burnt, of course it reflects a poor standard.

    And poor practices. A good standard anticipates what the market will do. They did not anticipate different product makers having a different interpretation of “default”.

    but as long as nothing breaks, I’d consider it as foolproof as anything reasonably can be.

    It’s now clear why you have no problems with the standard – you have a low expectation. The Lenovo PSU that supports 5v /should/ be able to charge a 5v appliance. But they botched the negotiation and absence of it. When both sides of the negotiation are compatible in terms of physics but they cannot work together because of a miscommunication, it’s a shitty standard.

    The whole point of a standard is to establish an expectation that different components /function/ together. Doing that without fires is a given but not the end game.

    The blog shows situations where voltage is substantially less. It’s a general rule of thumb that supplying too little voltage usually does not damage things, but I do not think that is absolute.

    That’s just how electricity works.

    I was describing how /people/ work.




  • I’m getting the sense from your comments that you think that USB-PD will deliver a higher voltage than requested. This is not accurate. A device can request any of the voltages specified by PD, and the power supply will supply that voltage if it is capable of doing so. If not, it will provide 5V. It’s very possible to get a sippy that won’t power your device,

    See the experiment I linked in the post that you replied to. If 19.5v is requested, 20v is supplied. If 12v is requested, 9v is supplied (not 5v). But also since 9v is optional, some PSUs would push 5v. So the voltage you get depends on what the PSU makers feel like sending.

    but a working, PD-compliant power supply will not damage a working, PD-compliant device.

    Yet they will fail because compliance is subject to interpretation and the ambiguities are disputed. Try plugging a USB-C bicycle light into a Lenovo USB-C PSU. Even though they both handle 5v, it fails. The Lenovo device makers believe all voltages, even 5v, must be negotiated. The bicycle light makers believe a 5v “default” /means/ they should get 5v without negotiation. The Lenovo PSU makers believe “default” means 5v will be the result of a failed negotiation (but not absence of negotiation).

    And other device makers believe USB PD requires supplying the closest voltage when negotiation fails, not 5v. Those people probably also believe 5v should be sent in the absence of negotiation.

    Obviously, if you get a barrel jack adapter that requests 20V and then plug it into a 5V device, you’re going to let the magic smoke out, but that’s because barrel jacks don’t do negotiation. The power supply correctly supplies 20V as requested, and then you plug that 20V into the wrong thing.

    You’re mixing up the different adapters. You can have a USB→barrel and you can have a barrel→USB. The interesting case is what I described, when the appliance and PSU are compatible in terms of voltage but still fail because of the protocol. Also consider that a 20v barrel PSU could feed a dumb usb-c adapter which then fries a 5v device. In principle, the adapter /could/ do a negotiation and refuse to supply 20v to a 5v device, or even just cut-off anything above 5v, but the shitshow that we have is a marketplace with dumb adapters. And in both situations (usb→barrel and barrel→usb), it’s not foolproof. Countless consumers cannot handle the voltage matching task so if the plugs fit, they will try it.




  • That’s no part of USB spec

    Do you mean the USB PD spec? It does not violate the USB spec which sets a default voltage of 5v. The adapter /might/ violate the USB PD spec if it were to claim to be PD compliant. But the shit-show we have is that USB-C does not imply USB PD. And so the market is full of USB-C things that are not USB PD. Often they do not claim to be USB PD as consumers are not wise enough to demand it. AFAICT, USB-C devices that do not mention USB PD would stand up in court.

    Note as well the adapter I mentioned is quite dumb – just hardwires pins for the situation that the appliance expects 5v without negotiation. Naive consumers could get burnt for sure whenever exceeding 5v.

    But it would be possible to implement a USB PD-compliant adaptor with the smarts to handshake, which would then refuse to complete the handshake in the event that the voltage supplied is not that requested. Of course it would be a bit strange to put that much sophistication into it which I suppose would drive the cost to that of a whole compliant PSU anyway (thus defeating the purpose). But notice the opposite has been done in a compliant manner, whereby the barrel adapter negotiates a USB voltage on behalf of a barrel device.

    as there’s no way to communcate requirements through the barrel.

    IIRC, it’s disputed whether the hanshake negotiation is needed for 5v. Some appliances expect to do a handshake /no matter what/, and some 5v appliances are designed to skip the negotiation entirely. If you are in the camp that says even 5v must have a handshake negotiation, then you would condemn the simple barrel to usb-c adapter (but perhaps not one that is only for a fixed input and the circuitry to do the negotiation).

    Hard to blame USB for when we side-step it’s design.

    The blame was not pin-pointed. I pointed out a shit show in the marketplace. There are bits of the standard you can blame (ambiguity and also having optional voltage steps), and you can also blame market actors. You can probably also blame regulators for not preventing the shit show that I described. And perhaps even blame consumers for not insisting that what they buy is tagged as USB PD complaint.


  • USB PD is also a shit show. You might want to read this:

    https://goughlui.com/2025/12/01/tested-usb-c-barrel-connector-adapters-5-5mm-od-2-1-2-5mm-id/

    Which shows those USB PD negotiations can get dicey. It chooses voltages thought to be close enough to what’s requested.

    I’ve run into a nasty problem where a USB-C appliance needed 9v. Says in the manual something like “only use Kenwood power supplies on this device”. I thought, fuck that, USB PD is a standard for a reason. I’m not going to blow money on a proprietary OEM Kenwood USB-C PSU. Then found that many power supplies actually skip 9v. The USB PD standard makes some voltage steps optional, and some mandatory. IIRC, 9v was one of the required ones, yet it was easy to find USB-C power supplies that skipped 9v but offered 12v (or 15v, I forget). And yet 12v or 15v was one of the voltage steps that’s optional. And IIRC, the Kenwood OEM PSU /only/ did 9v, which is also not USB PD compliant, so the Kenwood PSU could not be used on other things.

    So the USB PD strangely and arbitrarily makes some voltage steps optional, and manufacturers ignore the standard anyway.

    I have an adapter that goes from barrel to USB-C. Recipe for disaster. Even if a 9v PSU uses that adapter and a USB-C appliance wants 9v, it will fry shit because any non-5v appliance expects to negotiate the voltage. I don’t recall how it leads to frying (I think b/c it tries to start at the 5v default before negotiating for 9v but instead it just gets hit with 9v), but the fact that there are USB-C-barrel adapters that just hardwire without the needed logic is scary.


  • So in the context of copious dumb users plugging in anything that fits the socket, the data PIN may¹ have prevented a lot of damage while at the same time enabled HP to rack in lots of money on replacement OEM proprietary PSUs. Indeed I have seen on many occasians clueless plebs at the street market selling 2nd-hand appliances and quickly trying barrels from a pile of tangled PSUs until one fits, then trying to include that with the device they are selling without looking at voltage or anything. It’s common and I’m sure lots of gear gets fried because the general population is just not smart enough.

    I know how to match voltage, polarity, and current demands. And I got stung by the nannying to protect me from myself. Spent a lot of time disassembling a laptop, trying different RAM sticks, removing wifi cards and other components as I was baffled about what this fucking blicking LED means when it is not blinking in any way to convey an error code. Removed the CR2032 battery to reset the CMOS. Wondered if my slower than spec DDR3 RAM was causing this, so I went to the trouble of tracking down a RAM stick the precisely matched the specs. Still just got a steady non-stop blink, which the manual falsely states means it’s in sleep mode. So I was ready to conclude that the laptop was trapped in sleep mode and irreparably hosed. Perhaps I would have tossed a working laptop.

    Whether it is a good design to protect from incorrect PSUs (despite that the obscure barrel connector is probably only 19.5v systems anyway), most certainly it’s a crappy design to not inform users. To fail to assign an error code. Sure, it vaguely says in the manual something like “use only approved HP power adapters” – something /smart/ consumers do not take seriously because they know how to match PSUs to appliance and know that shit is always a branding hussle. The data pin should not be a secret that is concealed from both the user guide and the maintenance and service guide (which HP says is not for end users… yet they still withhold the info from service people).

    Perhaps good design as far as the PSU goes. But shitty to not document the situation and to not implement an error code.

    ¹ I stress /may have/ prevented damage because I have seen a lot of street market goods and only seen this obscure barrel tip on HP and Dell laptops, both of which are 19.5v.