points
Secure boot with software attestation could also be used for good.
There should be a physical button inside the case labeled "set up secure boot"