He forgot to mention another way to protect this attack from working if your UEFI has the option to disable the boot logo. Disabling it will effectively eliminate this attack vector. This is specially useful for older motherboards that will never get a proper bios update to tackle this issue.