Maybe what could happen though is that when booting the operating system, instead of reading whatever code normally runs as the kernel launches, some malicious code could be sent to the processor instead
I'd like to see the firmware decode/encode the MBR or MBR-equivalent. Encryption only being available if someone sets a jumper on the mobo during OS installation.