> for example you can write a rootkit that lives in the southbridge controller
Those two slides sets don't claim to have a rootkit 'in the southbridge controller'. The second speaks about Option ROMs, which are a well-known attack vector (see practically half the Thunderbolt attack concepts, the other half aiming for the DMA capabilities).
Option ROMs exist on plugin cards (which aren't southbridges) or, for built-in devices like on-board NICs, in the flash part that also hosts the PC firmware (BIOS, UEFI, coreboot, ...) - which sits behind the southbridge, not on the southbridge itself.
There's also firmware for auxiliary processors (eg. IMC or SMU in AMD chipsets), but that also sits in the main firmware flash.
The "security" processors (ME on Intel, PSP on AMD) also fetch their firmware from the main firmware flash (shared with the CPU firmware).
The location of various firmware items is pretty well-known. I'd be more worried about some extra chip (such as a discrete audio codec chip ;-) ) coming with its own rewritable flash memory. But that's unlikely for cost reasons and also not part of the discussion in security research papers, at least as far as I have seen.