My understanding may be limited, but I think the attacker can't do that (put something nasty into /etc/inittab or whatever) because I supply a passphrase for my encrypted filesystem at boot time. Hence, they have to nobble a bit of the system that's before that and capture the passphrase when I type it.
Re: I don't understand the threat model around boot security