I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive?
On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB.
Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76’s Coreboot doesnt allow such things.
I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot.
This one: https://libreboot.org/docs/linux/grub_hardening.html#grub-password
seems to only lock the ability to edit the grub entry freely, aka press “e” to change stuff when grub fails to boot.


In my example I’ve said that would be a prejudice. It is still more common to talk about a teacher as a man unless their pronouns are known, but they don’t give a fuck when it happens. I got called by both feminine and masculine pronouns in legal paperwork; it’s not a big deal and that comes from someone with a social gender dysphoria.
Name, next referred to only as person. And then feminine suffixes in upcoming legal fluff, because person is always feminine. Or a prosecutor and the rest is instead masculine. It is truly at bottom of a barrel of social problems and would require an eradication of multiple languages as they/them becomes used around B2 level of english and even then it slips, because mother tongue is a mother tongue.