Comment by zahlman

2 hours ago

This is only applicable if you already have root (in order to get beyond that), right? It doesn't expose new risk of local privilege escalation?

Reaching into ring -2 or the TPM allows privilege escalations past traditional "root permissions" and lets attackers defeat the sort of tamper protection that's designed to make escalations to local root manageable. Wipe-resistant malware, falsified cryptographic attestations, all sorts of fun.

This is more about getting at the code that device manufacturers attempt to hide from the end user. Platform keys, secure enclaves, etc...