Windows registry is in itself insecure. Applications can't own perms to their own entries.
Look at what people are using and optimize for that. Clearly the intended system is wrong, and ego death is necessary to create real fixes.
The easy and expected fix being that applications get perms for their own folder, rejecting 3rd party by default.
The proper larger solution being open code signing. But MS and friends are making big cash so they don't care.