I'm well aware, hence why I was just focusing on the 'main' machine in my post. If you extrapolate it to the entire home network, then defense in depth is the name of the game. Thing is, the only really viable option for a hardware gate / firewall that has no IME/PSP or other root boot niggerkit is an OptiPlex 3050 Micro. Power draw isn't horrible, but definitely higher than your typical dedicated box. Maybe something that supports Coreboot like protectli or is ARM based (I know they have their own IME style backdoors, but I do believe the implementation is less severe). An OpenWRT router already covers most of my bases, but you can never be too sure, so a dedicated front facing hardware firewall is most certainly on the docket.