boot guard would be even better if advanced users had an option of having their signing key flashed into the chip. Then you can have best of both worlds. Coreboot team can sign the firmware and owner can verify and re-sign. Or build on their own and sign.
Re: boot guard would be even better if
And please no NDAs.