And how does the device know that it is the owner of the device trying to flash it and not an attacker wanting to bypass secure boot? It's safer to have it assume that everyone flashing it is an attacker.
I don't think making secure devices should be made illegal. People who want to buy insecure devices are an outlier which means there isn't much demand for a purposefully insecure device. Using the legal system to force manufactures to purposefully make insecure things doesn't seem right to me.