> Google sells phones with unlocked boot loaders
They also sell carrier editions with locked boot loaders just like everyone else. Locking boot loaders is usually a carrier requirement imposed on manufacturers, not something OEMs arbitrarily decide to do, unless you're TP-Link.
> have similar "Developer Mode" support for Chromebooks.
CoreBoot on Chromebooks is just as locked down as UEFI Secure Boot if not more so. The RW Firmware isn't loaded unless the RO Firmware permits it and you can't modify or replace the RO Firmware by software. It requires hardware modification. Enabling Developer Mode on a Chromebook is analogous to disabling Secure Boot in UEFI.
> Samsung and Apple to the best of my knowledge do not sell unlocked phones but do sell unlocked laptops).
Samsung UEFI laptops have been known to brick if you try to boot Linux, not fail to boot but BRICK. Apple's laptops are absolutely locked down using EFI, you can't install any other OS unless Bootcamp allows it.
> Microsoft requires, on x86, that trust of the MS key be preinstalled and that it be possible to turn off UEFI
Secure boot is a security feature that validates code prior to execution via PKI in a signature database. The PK, is created and owned by the OEM and it can add KEKs from vendors (or distros) to allow them to sign their code. This database is owned, controlled and populated by the OEM, not Microsoft. Microsoft has no control over it beyond making their software refuse to function on not compliant systems. However the purpose of the feature is the inverse of that. That being said, there are several Linux Distros that support Secure Boot and offer PKIs for vendors.
Starting with Windows 8.1, Microsoft requires that new systems support Secure Boot have it enabled with Microsoft's PKI. That doesn't stop you from disabling it to use another OS. It doesn't inherently lock anyone out using whatever software they want, that decision is made by the vendor. The whole point of the system is to protect users from a compromised system, if someone tampers with Windows or it's drivers then the UEFI will refuse to boot it. It has absolutely nothing to do with locking people out.
Now on their RT/Mobile devices you can't disable UEFI Secure Boot. That's akin to locked ROMs and it's a requirement from Microsoft. There's no expressed reason for this but it's obviously because Microsoft gives OEMs subsidies to make Windows RT/Mobile devices so the hardware is often less expensive than comparable Android hardware. The last thing MS wants is for people to replace Windows on the devices with CyanogenMOD.
> They've started with restricting kernel drivers in the "anniversary edition".
Your implication is that this is a user hostile action when it's really a security measure to prevent naive users from installing hostile drivers. You can disable the feature by turning on developer mode. Now that's ok for Google's Chromebooks but not Windows?
You're attacking Microsoft for things you're giving everyone else a pass on.