Debian still supports UEFI, just not Secure Boot (which is not very secure these days if you're using a Microsoft-signed key).
AFAIK, Secure Boot is still secure on x86_64, at least if you trust Microsoft to not be doing something (either deliberately or unintentionally) malicious.
* The key isn't actually exposed, but a signed binary that will run unsigned code has been-- which allows secure boot to be bypassed without turning it off on affected systems.
It's things like this that make me want to try using an FPGA dev kit as my next motherboard. Not because the FPGA is relevant to this, but because it demands a lot of the high speed components (CPU cores, RAM controller) that a desktop computer would have.
Mind you, having an FPGA running the show would be the ultimate in extensibility.