That Ubuntu "let's make GRUB more secure by forcing a ton of use cases onto an unsecure path" is some specious BS.

https://www.phoronix.com/news/Ubuntu-26.10-Lighter-GRUB

Ubuntu 26.10 Looks To Strip Its GRUB Bootloader To The Bare Minimum For Better Security

Ubuntu developers at Canonical are looking to strip the signed GRUB bootloader features to the bare minimum for the Ubuntu 26.10 release later this year

@tychotithonus wow holy shit they want to remove LUKS support from GRUB based on their (IMO misguided) preference of doing LUKS from an initrd. I hate that design pattern, but I guess they have their reasons. Personally my linux laptops that are FDE encrypted are *completely* encrypted and boot leveraging GRUB's LUKS support. It's unusual, but I believe more resilient to bad shit.