Specifically I'm critical of the original post labelling any 'it is actually ok' message on secure boot as 'scaremongering'.
> Instead they declared themselves rulers
This statement logically suggests that Microsoft laid down the law on secure boot and the impetus was entirely theirs and nobody could have done anything differently.
The UEFI forum was made into a public forum for the public version for x86. Before that it was a proprietary boot protocol designed by Intel mostly for itanium but also licensed to Apple for x86 (2010 era Mac minis use efi). Microsoft were not the originators, although I've no doubt they're contributors to this and secure boot.
Where Microsoft _do_ dictate is the Windows logo program, which is distinct from UEFI. This was the discussion originally on Matthew Garrett's blog: will they or won't they leave an 'off' option (practically they had to, to boot older windows and rescue disks).
Furthermore Microsoft's Windows logo requirements, while requiring OEMs to carry their keys on the basis OEMs want Windows logo, didn't exclude the likes of Redhat or Canonical from standing up a CA and getting included. There's some discussion of this on Matthew's older blog posts: https://mjg59.dreamwidth.org/6503.html?thread=194919 although I think there was a better discussion on OEM inclusion I can't find.
In other words we find ourselves where we are because everyone has been content for years to simply use the shim signed by Microsoft. Only Microsoft stood up a CA and underwent the due diligence. And you can't say a free CA can't be stood up, because letsencrypt went from zero to cab root programmes in this time.
The only issue in here that needs some care is forcing vendors to ship all approved CAs, not a minimum selection they care about.
Bootkits are a minor issue now as othe commentators have insinuated because of secure boot.
There are other advantages, too. With secure boot and tpms remote attestation of some systems at least becomes a bit more reasonable. You can also have the same bootkit resistance under Linux if you're prepared to put in a little bit of effort.
Sure if I had my way we'd have prioritized MTE/PAC over secure boot but there you are.
So let me sum up. Yes, what Lenovo is doing is bad, and if Microsoft are really proposing ditching third party signing then they deserve another massive antitrust suit. Looks like Matthew is again pretty much the only voice in the Linux world trying to make something practical work.
I am saying that it should always be the case that you can disable secure boot and it should always be the case that you can manage your platform keys. I also think they should ship the UEFI CA by default and offer the option to opt in to secure core as part of Windows' OOBE if they feel so compelled.
But there is a non profit neutral third party already and no Linux distro (or the Linux foundation) have pushed for CA inclusion that I know of.
UEFI and Secure Boot are here to stay unfortunately. That's not going to change (and that's more of a comment on the design of UEFI than SB).