I still genuinely struggle to understand the advantage of UEFI/Secureboot whatever over BIOS. I own a piece of hardware, so I can do what I want to it. Out there, there is software, which I have to figure out how I'm going to trust, whether it's e.g Windows and I'm trusting that whole way of doing things, or Linux and that other whole way of doing things.
Stick a BIOS password on your machine and turn on Secure Boot. Unless there's an exploit in your firmware, you are now secure against petty criminals stealing your data to even somewhat sophisticated attacks from non-state actors via data exfiltration, software keyloggers, etc. You can go another step further and use Secure Boot in a chain of trust up to the kernel with Linux, ensuring everything up to the kernel fro…
Ordinary disk encryption would protect me too here, wouldn't it?