A jailbreak is not something Apple (or whoever) allows, it's a (serious) security vulnerability being exploited to gain root level permissions on the device and then circumvent whatever checks are in place. These are things that
should be fixed. It's also a cat and mouse game that is always changing.
> Does Apple have something like a "key" that would allow you to just run arbitrary software on the device? Is it something they would have to build, support, and maintain? I'm guessing this isn't a problem on Android and you can run whatever you want.
Not sure about the specifics of Apple's architecture (as it's also undocumented), but most modern secure boot systems have a hardware public key store (TPM) that any boot binaries must be signed with. Apple would closely guard those keys, and without them (and without security flaws), it is impossible to boot other code. Once you get a bit further along into the boot process, the architecture gets much more complicated as far as actually running apps, but it's all predicated on that secure boot key. Such a key store is probably possible to change, but Apple doesn't give any access to it from the userland, so users are unable to do so. It's also possible to make such a verification completely unchangeable in hardware; not sure if Apple may do it this way.
An open system would look something like UEFI secure boot, where the owner of the system can manage the keys in that hardware key store, to the extent of removing the manufacturer's keys entirely (which I think is also an important ability - what if I don't want Apple to be trusted on my device?). From there you can patch the OS to allow other code to run, though preferably this is something that would also be opened up explicitly.
Yes, it will require intentionally designing those capabilities into the products, but most likely it's not a significant architectural change, just a matter of giving users access to change the keys in the hardware they own.