Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
(www.welivesecurity.com)
Kind of. You can change the signing key for the operating system, but you cannot change the signing key of the primary bootloader, as that is baked into the SoC.