2 ms·
No, this isn't beyond evil maid - it doesn't require physical access, it only requires root access. Increasingly, root and kernel access aren't the same thing
by lorenzhs 6y ago
No, this isn't beyond evil maid - it doesn't require physical access, it only requires root access.
Increasingly, root and kernel access aren't the same thing any more (if you enable lockdown mode). That stops root from doing a whole bunch of things. It's true that often, user-level access is enough (if you only care about the user's data). But if you want to modify syscalls or do some other thing that root may not do in lockdown mode, you'll need to get kernel access. And many other ways of getting there have been blocked in an attempt to strengthen the barrier between root and kernel (some dispute the utility of that separation, but I think it's because they fundamentally reject its goals). This is about closing another hole in the barrier.
How useful that barrier is against attacks of the https://xkcd.com/538/ https://xkcd.com/538/ kind is, of course, a different matter. In my view, the point is that it raises the cost.