Sharing my checklist for buying a laptop to install Qubes

I don’t necessarily agree, for the reason explained here:

In other words, just because you can update the BIOS offline via USB doesn’t mean it’s automatically more secure than an online update, since some update blobs distributed for offline flashing via USB can’t be authenticated in any meaningful way, whereas some online update methods can be. If you download an unauthenticated blob, copy it onto a USB drive, then use that to flash your BIOS, you’re still accepting the insecurity of “online updates,” just with one or two extra steps in between (physically moving a USB stick around and copying some files onto it) that do nothing to improve security.