Just hit enter to get a shell of the rooty sort
phoronix.com
phoronix.com
The only obvious thing that can be done with this (beyond tampering with firmware) is to backdoor the bootloader/kernel/initramfs/etc, but that can be mitigated with TPM/TXT/tboot (just store your LUKS key in the TPM – any tampering will render it, and therefore your data inaccessible).
And in the case of "libraries, ATMs, airport machines" it is likely there will be no boot-time passwords at all -- regular login process will likely be more convenient for many reasons.