I'd be surprised if it wasn't just based off the UEFI sdk examples containing 30+ CVEs over the last couple of years. If anything, it won't get patched for logofail and all the others UEFI exploits we'll definitely see in the coming years.
Not even close, but It's my fault. I'm really bad at articulating my thoughts sometimes, and usually end up deleting my comments before someone calls me out on it. Sorry!
Sure LUKS will do what you tell it. Bitlocker will do what it wants and just use the TPM unless you jump through a bunch of group policy edits and such. But you are correct, I had forgotten it does give you the option to backup the key to a txt file during the installation or initial encryption process :)
Place bets with fellow travelers before tossing in a handful of mentos