if you rely on the os to mark protected sectors, the physical switch becomes moot. malware can just keep quiescent til a privileged action is required, especially if the switch is a disk wide all-or-nothing
also, system files aren't really the target here, the issue are userland files - who cares that the os is safe when the data is crypted
also, system files aren't really the target here, the issue are userland files - who cares that the os is safe when the data is crypted