Thanks lembas, that's a great option.
Thanks jxself, now I know how to do it, and why I should (or not).
The way I roughly consider my threat model is this: even if there's no threat
involved, if it's easy/takes little time to setup, it's better to have it
than not.
This could be a good option for computers that don't support libreboot and
can't have an encrypted /boot (since proprietary BIOSes typically do not have
support for reading an encrypted /boot it needs to be left unencrypted.)
Looking at this (https://wiki.archlinux.org/index.php/GRUB#Boot_partition)
and this (http://www.pavelkogan.com/2014/05/23/luks-full-disk-encryption/),
it seems I don't need to be on Libreboot in order to have a functioning
encrypted /boot anymore. Grub offers this exception now.
Even if I'm not on Libreboot on this machine, I still can boot manually. But
I can't figure out how to save my manual input. Yet.