I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive?

On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB.

Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76's Coreboot doesnt allow such things.

I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot.

This one: https://libreboot.org/docs/linux/grub_hardening.html#grub-password

seems to only lock the ability to edit the grub entry freely, aka press "e" to change stuff when grub fails to boot.

you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 3 hours ago

In my example I've said that would be a prejudice. It is still more common to talk about a teacher as a man unless their pronouns are known, but they don't give a fuck when it happens. I got called by both feminine and masculine pronouns in legal paperwork; it's not a big deal and that comes from someone with a social gender dysphoria.

Name, next referred to only as person. And then feminine suffixes in upcoming legal fluff, because person is always feminine. Or a prosecutor and the rest is instead masculine. It is truly at bottom of a barrel of social problems and would require an eradication of multiple languages as they/them becomes used around B2 level of english and even then it slips, because mother tongue is a mother tongue.

  • source
  • parent