Hey, I am working on a BIOS, which is also part of the successor of OCAV for MineOS, that includes full security, compressed file system, encrypted executables, and even signed BIOS extensions. Like maybe make a custom firmware extension (that would be named firmext.lua) for OpenOS, one for MineOS and another one for Fuchas... I made also a system that uses hashes to block potentially malicious firmware extensions ,because the firmware extension is made to run outside of my sandbox.
Interested ?