As far as I'm concerned, the kerfuffle betwixt "sercure" boot, and "restricted" boot is a digression from the main issue, whether or not users control their own systems, that they have purchased, and hence own. If they own them, then THEY should have all control over how the system is to be configured or behave. I they don't, then they are only RENTING their computer systems. Anything else, is a distraction. So, do we OWN our systems, or do we NOT?
Let the user choose