Why is it okay to reduce security to install kexts on an external disk or a MacBook Pro but not on his Mac Studio?
As you put it, it really is a desire for maximum security at play here.
Booting that computer from an external drive with third party kexts would also increase the attack surface, right?
"Just allowing kexts to be loaded" sure, it wont. But "just allowing kexts to be loaded" makes no sense as an action, unless you also actually intend to and do load at least one kext.
In which case, it absolutely increases the attack surface.