This is just a random thought:
Perhaps a more granular password protection level?
(I know that we can't do TOO much in this layer, but it would be nice to have more than power-on, and setup password.)
Of course, it would be good to have the BIOS MD5 or hash the password in some way to keep someone from reading /dev/nvram and getting said PW.