> at a minimum you want secure boot + attestation + memory encryption
that's an interesting statement. These all feel like patches to mitigate the evil maid problem, but they can never solve it fully