Forever Days, Silicon Immutability and the Crisis of Unpatchable BootROM Vulnerabilities in Cyberwarfare: Ethical and Anticipated Ethical Issues

Authors

  • Richard Wilson Towson University
  • Noah Donnelly Towson University

DOI:

https://doi.org/10.34190/eccws.25.1.4859

Keywords:

BootROM vulnerabilities, Hardware Root of Trust (HRoT), Vulnerabilities Equities Process (VEP), Anticipatory technology ethics, Cyberwarfare, Supply chain security

Abstract

Modern mobile security architecture relies on a hardware Root of Trust, which is a set of capabilities in a device’s hardware that functions as anchor for all security operations within that system. (Rambus Press) This is exemplified by components such as the Apple Secure Enclave (Touch ID or Face ID use a separate processor to handle your biometric information which is called Apple Secure Enclave) (Pot, 2018). However, the reliance on immutable Silicon, specifically BootROM code (Bootrom (or Boot ROM) is a small piece of mask ROM or write-protected flash embedded inside the processor chip (What is Bootrom). It contains the very first code which is executed by the processor on power-on or reset), introduces a very critical risk: the "Forever Day" vulnerability. Unlike software flaws, vulnerabilities within the BootROM cannot be patched once the chip leaves the manufacturing plant. BootROM code itself isn't used in cyber warfare; rather, vulnerabilities in BootROM become powerful footholds for: persistent espionage, secure‑boot bypass, hardware‑level compromise, supply‑chain infiltration, cryptographic key extraction, attacks on critical infrastructure devices. Because of its immutable nature, a single BootROM vulnerability can become a strategic cyber weapon—especially for well‑resourced nation‑state adversaries. Ethical issues arise due to how malicious adversaries could exploit the immutable nature of BootROM vulnerabily. According to Furrow ethics is related to the intentions, actions and outcomes produced by agents involved in decision making. To intentionally manufacture technology with vulnerability built into immutable silicon is an ethical issue. This analysis, using case studies investigates the technical outcomes of such exploits, where a single compromised read-only sector renders millions of devices permanently vulnerable to compromise regardless of OS security updates. We further analyze the tension between the commercial imperative to rush new silicon models to market for profit and the rigorous security validation required for immutable code. Finally, the paper discusses the role of state actors, such as the NSA, in the disclosure versus hoarding of these hardware level exploits. We conclude that "Forever Days", (a Forever Day bug refers to security vulnerability in a software application or system that remains unpatched for an extended period of time ) (Forever Day Bug, 2023) represent a fundamental failure in the current hardware lifecycle, leaving a permanent window for exploitation that persists for the lifespan of the physical device. The analysis will conclude with an ethical and anticipated ethical analysis of BootROM code when it is used in support of cyberwarfare.

Author Biography

Richard Wilson, Towson University

Richard L. Wilson is a Professor in Philosophy at Towson University in Towson, MD. Teaching Ethics in the Philosophy and Computer and Information Sciences departments and Senior Research Fellow in the Hoffberger Center for Professional Ethics at the University of Baltimore. Professor Wilson specializes in Applied Ethics teaching a wide variety of Applied Ethics Classes.

Downloads

Published

2026-06-15