>I know I could bypass normal password-based FDE with physical access to a machine without any special hardware or software
How?
How?
Actually, on second thought, it's secure boot that protects against this attack, which doesn't require or use a TPM? So maybe I'm wrong