@magnetic_tape That might be a good idea for security, reminds me of how some Chromebooks require removing a physical screw (which breaks a circuit) to flash the firmware.
But in this case it wouldn't help because the UEFI just loads an image from the unencrypted EFI FAT32 partition 🤦