Demystifying UEFI, the long-overdue BIOS replacement
extremetech.com
extremetech.com
All of the UEFI systems I have encountered have native UEFI firmware in flash. On top of the UEFI environment, most shipping systems have a compatibility layer (CSM) that exposes a legacy BIOS emulation to allow traditional MBR-style booting. It is possible to load an EFI environment on top of a legacy BIOS (UEFI DUET), but that isn't usually how it is done.
There is no special bootloader; OS bootloaders are just UEFI applications in a specially-named path on each drive that the firmware finds and lists as boot options.
The mouse-driven GUI is a feature of some specific implementations, not part of UEFI itself.
UEFI is turning into a huge mess. I'd look to the Coreboot stuff being pushed/supported by AMD as a much better path to the future, and try to think of ways to club Intel's NIH-adled brain into getting on board.
The other problem is, in the original article that was published on this topic, that apparently the Linux/grub boot process will be changing so that the "kernel is part of the bootloader", so I think that adds to the complexity of the idea of signing either the bootloader or "the whole OS" (whatever that means anyway.
Regarding the "kernel is part of the bootloader" idea, I think that was just an idea :) That's not happening anytime soon, although you can give Linux as a stage 2 payload directly to coreboot currently.