

I mean with physical access.
People living with you.
Or when you want to travel (domestically).
Someone who doesn’t need much experience can access the hard drive / SSD and replace the bootloader.
I know it probably doesn’t happen often, but this is more of a personal fear thing, I have trust issues with people.
Living alone is too expensive and thus I either have to stick with family, or split rent with random strangers as roommates, not to mention, some landlords can be creepy and do weird things. I don’t have trusted friends who can like live with me as a roomate and split the rent.
So anyways, I’m with parents, and I want evil-maid protections for peace of mind, since I can’t afford to live alone. (I mean like they are not dangerous criminals or anything like that, they’re just fucking nosey and I don’t like to find out how much do they want to spy on my online activities).
For phones, its already too locked-down and hard to modify so I’ll just trust the verified boot to do it’s job.
For computers, its too easy to edit the bootloader on the disk. So I think putting the botloader on such an encrypted USB and put it in read-only mode would protect against tampering with the bootloader.
I probably sound paranoid af right?
Basically, my threat model prioritizes preventing weirdos fucking with my electronics more than anyone else.
They’ll reverse the decision when those teens start saying “Stop Genocide” on social media.
100% guaranteed.