Comment Re:All bets are off if you have physical access (Score 1) 12
You don't need physical access to install a bootkit, just root access, and full disk encryption would only protect against bootkit infection via an evil maid attack. The bootkits being discussed here get install by just running on top of the full OS with root privileges.
But on the other hand, bootkits are an extremely rare form of malware, likely the rarest type, and I think creating Secure Boot in response to it was a case of whipping a curious little problem into a crisis and then never letting a crisis go to waste.