with your way of thinking this is insecure as BIOS/firmware can be always modified.your laptop, or theft/loss. The only way to get a "secure" system would be to have a fully encrypted disk, a BIOS that does the password management & boot decryption, and hardware (+ BIOS/firmware) that can't be modified
there is a limit after which people gets paranoid. I don't want to get over that.

