The Reality of Disk Encryption

You enabled LUKS during Debian install. You enter a passphrase at boot. You feel safe.

But here's what that default setup actually protects against: someone stealing your powered-off laptop and reading the drive. That's it.

What it doesn't protect against:

Someone tampering with your bootloader (no Secure Boot verification)