Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
(www.welivesecurity.com)
Functionally, though, wouldn't it be the same as replacing the computer's SecureBoot bootloader, since it's Microsoft (in the case of SecureBoot) that doesn't like the unofficial key that Linux installs? Shouldn't the user be allowed to add or remove any key they desire from the allow list of official keys (maybe have some sort of decentralized verification system, if they user decides they want to verify it)?
I'm more thinking out loud here, trying to understand.