You can always disable SIP and load unsigned kernel extensions, if they refuse to sign.
If you’re a power user, you’ve probably already disabled SIP.
A couple of releases ago files like /etc/hosts and /etc/sudoers were protected by SIP. That’s not the case anymore, though.
And if you’re deliberately installing unsigned drivers, the assumption should be that you (should) know what you’re doing. So disabling Secure Boot/SIP as a prerequisite for that is fine.
Or are you suggesting that everyone should be able to install unsigned drivers with 2 clicks? Because I’m not convinced that it’s a good idea.
Actually I am ("signing" with one CA only is mostly security theater and market control), but that's besides the point. The point being that macfuse will quickly become even more of a pain to install and use, making it more useless and not recommendable to end users.
Please don't go around another time and now claim "but you can disable SIP!" while at the same time claiming "but end users should not disable SIP!". We are effectively an end user here. If you "need to know what you are doing" to install macfuse then no one is going to install it.
It's exactly the same as with Secure Boot. No one wants the Scary Boot Prompts. No one wants the Scary Desktop Watermark. Your users will blame your product and avoid it.
If you could just whitelist one extra signature, then maybe there'd be something to discuss. But you can't.