Source? How is it possible to install malware when the disk is encrypted?
http://www.pcworld.com/article/2948092/security/hacking-team...
More advanced versions would involve modifying the BIOS to add a SMM-mode hook. That way the malware runs completely outside the view of the OS. Alternatively, any device with DMA access could have its firmware altered to read sensitive information from memory.
Physical security is an unsolved problem.
Mine isn't - I have GRUB installed to my BIOS chip, and I decrypt the single encrypted partition from there.
>More advanced versions would involve modifying the BIOS to add a SMM-mode hook.
That one could still get me though, yeah.