And certainly don't use another country's servers.

Especially ones that USA headquartered companies hold private keys for. Look up the Intel ME and AMD PSP. All that for your Hollywood's protection, you see -- there's no way to get an Intel or AMD machine without the unwanted megabytes of backdoor-capable signed firmware.

Thankfully non-x86 options exist, but they're not widespread yet. Maybe this will help give a bit of a shove in the right direction?

