An unencrypted boot partition opens the possibility for someone to be able to install malicious software, since it can be read from and written to without any problem.

Indeed. However, encryption only makes a difference in a scenario with physical access. That is, in this case, someone booting a Live system on the computer and changing the kernel in /boot.

Reply via email to