Yes, you could do that. But every machine would be shipped with Microsoft's signature installed, and Linux could only be installed if you were willing to type in a machine-specific password printed on a piece of paper you probably lost when you unpacked the machine. The problem here isn't coming up with technical solutions, it's coming up with technical solutions that the vendors would be willing to ship and which don't cause a different set of problems.
Re: firmware/hardware-level password protection as an alternative