You can order it dipped, wet, or dry. Wet is the traditional so it usually just has one or two ladles of juice poured over it. Dipped is when they dunk the whole thing. But the bread is high quality so it can usually take it. I prefer wet myself (hehe).
Bitlocker is extra vulberable because it stores the key in the TPM and requires no password to boot. An attacker can extract the key even if the computer is off when they get it.
This is not true.
You would additionally need to bypass Secure Boot with a separate exploit such as the one in this article (which is mitigated by disabling USB boot) or LogoFAIL to put the TPM PCRs in a state where the keys can be released.
LUKS2 is no different here as either can be TPM-only or require a separate PIN.
An SSO-like payment system with tracking and revocation is a great idea and would be amazing for us consumers. I'm just not holding my breath waiting for the corpos to implement it.
While nowhere near perfect (far from it, really), as long as the sites you are shopping on are PCI-compliant (most should be), you don't have to worry too much about a compromised site leaking your payment details for use elsewhere.
Basically just use a password manager and don't worry about saving credit card (NOT debit card) details in the site as long as they aren't extra-sketchy.
If you're willing to wait 2 weeks for shipping (with an added shipping cost of $0.40) you can just order that stuff directly from Aliexpress and cut out the middle man.
I'd be careful about completely trusting any AV to give you any certainty that you aren't infected.
As I mentioned in another comment, Pegasus is comprised of many different exploits. So just because Bitdefender can detect some older Pegasus variants, doesn't mean it can detect all of them.
In fact it's quite unlikely they can detect the latest variants.
I don't know the full answer, but Pegasus isn't one single piece of spyware, but rather a toolkit of many, many zero-day exploits.
A lot of them (the majority maybe?) are non-persistent meaning that they don't survive a reboot.
That said, aside from keeping your phone up to date with security patches and rebooting frequently, I'm not sure there's much the average person can do if you're actively being targeted.
Citation Needed