logoalt Hacker News

drdexebtjltoday at 6:05 AM1 replyview on HN

Not all package managers require root.

But yeah, maybe through an exploit with a narrow reach. Once in, the malware can veto security updates and escalate to full control.


Replies

self_awarenesstoday at 6:12 AM

With root, malware can reach out to UEFI anyway, and can do whatever it likes.