(A rain of downvotes falls on me)
Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please.
We need a fully signed and auditable chain of trust for booting OSes.
Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible.
And for the 1% of people who are going to bang about their right own the hardware and run Linux and what not (I'm definitely one of those), we need to be able to do it but in an obvious way (computer should boot but display a clear message that it's been tinkerer with).
I really like software freedom, but the fact that I can disable secure boot on pretty much any computer I have physical access to and that the user will never know about it is not okay.