Reflections on trusting trust is here. Sure, you can replace boot bios but it's been impossible to be certain all parts of your system have not been subverted for decades. Any peripheral with microcode which is updated is implicitly part of your trust model and most SD cards include an 8 or 16 general purpose CPU or a very generalised FPGA or better. Keyboards, mice, disk controllers, inserted devices, screen control logic is all outside your control before you discuss the CPU and OS you consider "this machine"