

You are just moving things. When you change your EFI partition from being unencrypted and asking for your password to the BIOS asking for your password (or other credentials) you just shift the attack surface.
Somewhere there has to be an unencrypted part to start with.
Lock your unencrypted ESP down with secure boot and your own keys (shitty as it is that is in fact the one conceptional usecase of secure boot, not that stupid marketing bullshit MS is doing with getting vendors to pre-install Microsoft keys) to prevent tampering and you are good to go.





That article triggered an unexpected roller coaster of “there is something called vimdiff I never heard about?” to “no, there isn’t because for me vim is just an alias for nvim” to “oh, it’s actually just vim -d anyway…”