Microsoft's secure boot key is compromised* on ARM, and it's not feasible to revoke and replace it.
AFAIK, Secure Boot is still secure on x86_64, at least if you trust Microsoft to not be doing something (either deliberately or unintentionally) malicious.
* The key isn't actually exposed, but a signed binary that will run unsigned code has been-- which allows secure boot to be bypassed without turning it off on affected systems.