"Reboot the machine, and go into the BIOS. Usually this means pounding on the F2 key as the boot starts up, but all machines are different, so it might take some experimentation to determine which key your BIOS needs."
That will be a show-stopper for most people.
The magic is in KeyTool and that doesn't require the user to alter the BIOS in any way. You boot from that USB drive (sb-usb.img linked in the article) by the usual methods of booting from an external drive. It will boot because its bootloader is the Linux Foundation one that was signed by MS. Then you launch keytool and change the key config.
At this point, your bios will boot a kernel you have signed.
The only BIOS intervention in the article was to first allow booting unsigned kernels (not needed with that sb-usb thing) and then to turn it off again. At least that was my impression.
Doesn't running keytool require you to turn off security in the bios first?
sounds like abomination. Even in the early 1998 our web browser had 4 or 5 root certificates. Why only one in the case of secure boot?