1. kernel and initramfs is loaded from unencrypted partition
2. initramfs calls a program called `donglecheck`
3. the program checks if the dongle is plugged in, if it isn't, displays the error screen
2. initramfs calls a program called `remoteinstall_s`
3. the program presumably asks the dongle for a key, which it then uses to unlock an encrypted root partition
4. boot continues from the encrypted partition