upvoted as we need as much visibility on all this mess.
upvoted as we need as much visibility on all this mess.
What are you referring to? And what's wrong with trusting the BIOS for that specific thing when you already trust it for everything else?
if you can't trust your BIOS, how are you going to be able to trust anything else on your system?
It all starts with the BIOS being (password or otherwise) protected to not be modifyable without authentication and then goes into secure booting your signed UKI (or whatever other signed way). From there you can have it mount your encrypted drive or load another signed root image.
That is like the minimum needed to be able to trust that what you are running is indeed something you can trust and nothing random has been inserted inbetween.