• fmstrat@lemmy.nowsci.com
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      21 hours ago

      But… your original comment is just… wrong?

      This isn’t a critical security flaw unless you have the worst partition scheme on your encrypted volumes imaginable.

      The default LUKS partition scheme is vulnerable.

      It’s not even a process flaw at that point, just “possible”.

      There is a successful POC, it is a flaw.

      you can compromise disks once encrypted because everything is happening in an in-memory boot process.

      This is not just in-memory. This is modifying the unencrypted part of initramfs on disk. Powering off the machine does not remove the exploit.