> Are you someone that needs to worry that a delivered device has been manipulated mid-shipment?
> If you try placing a simple LaunchDaemon on a Secure Boot device’s System volume, it doesn’t stop it from booting in Full Security mode. That’s not one of the things in the signature manifest.
With DEP/MDM the existing OS and files that were there doing shipment would still be there, DEP/MDM would just add additional things or change settings. With imaging you wipe out everything that was there during shipment and start fresh.
It’s not. They could hack the BIOS or the IME to establish a rootkit that is practically impossible to detect.
Performance is also a factor, as you mention. If you're onboarding hundreds of people in the same room at the same time, there's no WiFi in the world that can deliver the base config in a timely and reliable manner. One solution is to preload all the necessary bits, see for example Facebook's AutoDMG Cache Builder.
Imaging is still also by far the most automatable solution, and the only one that can truly be zero touch. It's possible to reinstall and set up a fleet of machines, with no human needed to touch them. DEP still requires a human with physical access to set up the machine on first boot.
While we've switched to DEP and MDM as our main deployment method, it still has a ways to go before it covers all cases.
https://arstechnica.com/information-technology/2018/07/hyper...