is it possible for vendors to ship a system like this that would also allow for users to encrypt their entire hard drives? Maybe it would be something like OS X firmware lockdown, but that is less convenient and takes away a lot of the options for the user.
Is this an either/or scenario?