3 ms·
Pardon my ignorance, but does “actual root” imply some kind of connection between a Linux root user and the motherboard chipset?
by eric-hu 3y ago
Pardon my ignorance, but does “actual root” imply some kind of connection between a Linux root user and the motherboard chipset?
- jpgvm 3y agoProbably not. They are probably referring to root of trust. Though they could also just be referring to "root" as a colloquialism to compromise the system but we are going to go with root of trust for sake of discussion. The motherboard (and associated UEFI/BIOS bits) is responsible for bootstrapping the Secure Boot process, it holds the keys that are used to verify the boot loader etc, which then chain-loads into a signed initramfs and kernel which then would normally decrypt and authenticate the filesystem. This chain of trust only works forwards. If you pwn any link in that chain then everything forward of it is now untrusted. Thus compromising the actual root, i.e the UEFI/BIOS firmware is the ultimate hack. Especially if it can be done persistently and without detection. Now for a normal desktop this doesn't really matter but on something like an EV (basically computer on wheels in Tesla's case atleast) then it really matters. High value military computers wouldn't be much different in this respect.
- yencabulator 3y ago"root" has come to mean "unrestricted access", e.g. "to root" = "to gain unrestricted access". In this case, it most likely refers to a network connected hardware subsystem that can pause the main CPU and access its state freely.