That's one of the reasons I've been working on signing tools. In the event of some major policy shift - or the case that you don't trust Microsoft at all - at the very least you'll be able to sign your own bootloader for your systems. The current tool is at github (https://github.com/vathpela/pesign). There's not much documentation just yet, but I'll be working on that sometime in the upcoming weeks.
Re: Options are not mutually exclusive
-- pjones