Completely agree. My sarcasm did not quite show through in my post. I've always found UEFI security to be more to do with financial security for Microsoft whereas malware can bypass all of that, same with the evil maid agency stooges and that's even before getting into JTAG debugging on most devices. I see UEFI certificates as security theater.
this doesnt put good light on MS, but is no where as colossaly incompetent as the progressive destruction of windows.