What is the best option for boot security for Qubes?

What is the best way to protect boot security with Qubes? I have read about AEM, Coreboot, Heads, Libreboot etc. Is AEM the only working option at the moment? If I am using a fairly new PC with an Intel i7 which option is best that currently works with Qubes OS? It seems these other options libreboot, heads, etc only work for a select few devices. If it is between AEM and Me_cleaner which would be a better choice?

1 Like

what’s your threat model?

1 Like

I don’t know your Threat Model but
I would take Coreboot over AEM / AMI

I would also take an Intel with ME_cleaner over AMD right now, maybe AMD will be back on top again one day but currently I have reverted back to Intel