It's silly to pretend a BSD OS is going to be immune of the consequences of an EFI which is compromised at birth. Sooner or later there will be a value chain in compromising my OS, through the EFI.
I wish we had better out of band EFI validity checks, based on what the manufacturer thinks should be there, as a reproducible bitstream.