> I can not possibly see how a system that does not leave the owner of a system firmly in charge can make any sort of sense.
You are firmly still "in charge". You can install your own keys, and you can disable this feature altogether in the firmware. On x86, nobody is stopping you from that.
ARM Client machines are a different story. On Windows logo-bearing ARM client machines, you are not in control. That's why we've said we don't intend to support this functionality on ARM.