TFA:
> If your hardware is vulnerable, mitigation can be achieved through the use of a PIN.
Or, encryption passphrase on boot.
But in that case, you just need two accesses: Add h/w keylogger, read h/w keylogger.
You can at least make it somewhat more difficult by using ubsguard to prevent the most obvious keylogger ingress points.