There is a freely-available kernel extension[1] to make this firmware hack accessible to root only. The exploit depends on modding the camera firmware from userspace.
The kext is created by the same authors of the paper[2] this article is talking about. Search the paper for "iSightDefender".
[1] https://github.com/stevecheckoway/iSightDefender
[2] https://jscholarship.library.jhu.edu/bitstream/handle/1774.2...