Earlier quoted context omitted.
If you read through the slides @ https://github.com/jbangert/trapcc/blob/master/slides/PFLA-s... there is potential to bypass hardware memory protection. Very interesting.
Ahh, ok. Might actually be enough to, say, copy an encryption key out of kernel memory then?
Unless the encryption key is guarded by something with SMM privileges -- has that been done?