this post was submitted on 13 Aug 2023
733 points (93.5% liked)

Memes

44108 readers
3043 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] MooseBoys 1 points 10 months ago (1 children)

While WEI definitely doesn’t qualify as a rootkit itself, any useful attester is going to require aspects of one - whether it’s a phone asserting that it hasn’t been rooted, or a PC running with approved SecureBoot and TPM keys.

[–] FlexibleToast 2 points 10 months ago (1 children)

That's still not a rootkit. What do people think rootkits are?

[–] MooseBoys 2 points 10 months ago (1 children)

Sure it is. A rootkit is a mechanism for hooking access to highly privileged execution levels of a device, masking its own presence, and persisting itself against removal. TPM + SecureBoot runs in firmware, more privileged than kernel mode. It analyzes the bootloader and other key boot parameters to verify they have not been tampered with. They can’t be disabled from within the OS. And sometimes they can’t be removed or disabled at all without someone finding a vulnerability, as in the case with phone rooting.

[–] FlexibleToast 2 points 10 months ago (1 children)

Great, but using the TPM as intended is not a rootkit or anything like a rootkit. It's using a security device as intended.

[–] MooseBoys -1 points 10 months ago

Although often associated with it, a rootkit does not inherently need to be malware. In the case of phones, and likely future PCs, they are used to prevent users and owners from modifying their device.