It says here that you are able to add 2fa login to ubuntu with the yubikey, see link, =pfVhAtJt5_o&t=137s. But I guess this doesnt help if you are able to access recovery mode and change the bios from there and swap the bootorder or something. then they can open the lock because they can make their own program for the lock in their own bootdrive.