Yikes

Matt Rice <[email protected]> Sat, 30 Jan 2016 11:46:17 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <CACTLOFo_yuoCQQUb_tkt8kuxoF0KkWqFrosnDcVpCGSXsbb4dw@mail.gmail.com>
Coarse (filesystem mounted read-only vs read-write) permissions
ambient authority
writing to the bios/storage that doesn't appear able to be checkpointed

what could go wrong?

https://github.com/systemd/systemd/issues/2402

all so that an enumerable number of programs that install bootloaders
can write to them...

the 'storage that cannot apparently be checkpointed' aspect, makes
this a particularly dangerous capability even on cap systems which can
grant access to the enumerable programs.