I think it's now two decades since I first found how to overwrite BIOS passwords from MS-DOS QBasic in order to break into school computers. Somehow reassuring that kids are still doing the same thing.
The comments about bitlocker and TPM are a good reminder that he who controls the boot sequence controls the computer / phone / car / IoT toaster.