I guess it could be made pretty secure with good old code signing. Most distributions already sign their packages, but as this concerns the booting process it could be somewhat more difficult.