tbh, wish i could do a proper self-enrolled encrypted-drive-plus-secure-boot thing, but then id have to deal with UEFI, the TPM, making sure everything properly reenrolls again whenever a grub/kernel update happens, and more bullshit. plus the UEFI is probably vulnerable anyway
feels like just putting the luks header on a separate drive i carry with me at all times is a better idea