I heard about some draft or proposal about how BIOSes are vulnerable to local attacks, making the computer compromised.
I haven't read all of the huge PDF file yet but I know that closing down BIOSes on devices so that you can't flash your own BIOS on your x86 or video card, HDD/SDD/optical/mobile device hinders innovation, freedom of choice, creativity and learning (say if you want to learn about BIOS modding). You might not be able to even read off the BIOS, not sure.
Imagine having to update the BIOS remotely by linking with a server somehow and with encryption.
Hopefully if this does pass, we will find a way to emulate the server or something and inject BIOS code somehow to our own computers. According to the PDF you could take out the flash chip and replace it with one that has the modded BIOS in it (yea, sure).
Here is the PDF.
NIAP_CCEVS: U.S. Government Approved Protection Profile - Protection Profile for BIOS Update for PC ...Email
niap@niap-ccevs.org and(or?)
pp-comments@niap-ccevs.org about your concerns and spread this around!
In my email to them I mentioned how manufactures often don't develop features that people want or bug fixes BIOSes because they don't want the development costs or don't think it's important. I made a few examples.