First real-world usage figures suggest Chromebooks are struggling
zdnet.com
zdnet.com
In a normal boot, the computer loads a read only firmware. It then checks the file system for kernel images. At this point, it finds the newest one (with a valid cryptographic signature from google), and boots into that. If none of the kernels are signed, then it enters a recovery mode.
However, every chromebook has a physical switch to put it in developer mode. In this state, the cryptographic checks are no longer performed, so you are free to load your own OS.
The only problem with this system is that if you want to load your own kernel, you are stuck with the security of every computer before secure boot became common. Seeing as that is still most computers, (and I do not see what benefit google would get from reguiring users to surrender that benefit), I think this is reasonable.
It would, however, be nice to be able to modify the keystore and load my own verified OS. Thankfully, there are plenty of UEFI systems that support this.