Your initial comment was a bit brief; Now I realize you meant "just use full disk encryption/luks with the bootloader and boot-partion on a removable device -- to lessen the chances that the password prompt has been modified to capture your password (back-door bootloader, backdoor kernel/initrd)".
Still somewhat vulnerable to a replaced BIOS and/or a hardware key logger (I gather the idea is: I can keep my usb key safe easier than my laptop. I'm not sure if that's true in a meaningful way).