Whenever possible, please perform the new installation using minimal security settings. For desktop users, it's highly recommended to create a fully encrypted root system using LUKS. Additionally, activating secure boot (UEFI) with or without SHIM is advisable. Also, consider using the debian-sources kernel with module signing support, enabling you to boot your Funtoo system with module.sig_enforce=1. Remember, not using LUKS today poses a significant security risk.