A lot of modern BIOS/EFI also allow a hybrid setting that enables legacy support until the OS takes over, which can sometimes be better too.
My parents let me decide what I needed to see and learn how to customize things for myself. That seems like a sane default to me.
Addendum: You could say you want a sandbox, and that such is part of the sandbox to play with. Then you need some kind of way to clean up, like you can clean up the toys your kids play with (or ensure they clean up their own mess), or ensure their sandbox environment is safe (such as no fire hazards in your house). Then I would argue a VM is such. OS with rollbacks or a user account on an OS or locked down iOS/Android could suffice, too.
My parents gave me the bicycle in a box. I had to put it together if I wanted to ride it. They owned the bicycle shop too. They could have put it together for me, but they let me do it.
- The firmware
- The bootloader timeout
- Waiting for the user to type the encryption passphrase
Everything else takes almost no time at all. So, if you can eliminate 5 seconds from the boot process in the normal case, without eliminating your ability to debug the system in the unusual case, that's a win.
Or, if you're working on speeding up virtual machine boots, in which case you skip the bootloader entirely and use the kernel's EFI stub.
"I never let that happen." Cool.