> Do the official LineageOS releases have Verified Boot (allow you to lock the bootloader)?

Possible in theory, but complicated:



These attacks require physical access to the device, and a rather sophisticated adversary.

If the attacker has physical access to the device, they could plant a camera to get the passwords or use a $5 wrench, etc.


At that security level, you can't trust a single device, and you'll probably need to look at security solutions such as hardware security keys (Yubikeys), Shamir's Secret Sharing, plausibly deniable encryption, etc.

