And here's where many of us here, including me, differ from Apple:
"We agree with Apple that security is at the heart of all data privacy and privacy rights. Where we disagree is in who holds the keys. Your data isn’t truly private or secure, if someone else holds the keys."
@ddipaola That screw sounds like a good idea. So you screw it in and it'll block your BIOS settings changing until you unscrew it?
@alcinnz yep! the screw is in by default and bridges two pads on the PCB that forces the write pin of the SPI flash ROM (containing the firmware) to "off". when the user wants to enable firmware writes, remove the screw, then put it back in to guarantee that even malware with root access can't flash the chip!
@alcinnz citation on the write-protect screw: https://libreboot.org/docs/install/c201.html#removing-the-write-protect-screw