I have mixed opinions but there was a recent  device driver trick
that has the potential of protecting the MBR.


It might be possible to extend this model to the last blocks on
the disk.   Then use capabilities and device permissions
to this end.

A physical  hardware device can trigger a latch and disable the bits
once a region is accessed.   Old time BIOS systems had the
BIOS/ROM at zero and after initialization a latch was flipped and
the BOOT ROM was moved or made invisible.
Power-On will reset the latch but no software path could.

