You apparently miss the point of the original post. The poster wants to know why they don't make it so that you can decide what keys are trusted and add your own. Saying that they don't make it that way doesn't answer the question. I suspect that there is no good answer to the question. In fact, your answer suggests there is no good answer, since it is the equivalent of the standard, "because I said so," reply (or in this case, because the UEFI implementers said so).
Re: why is this needed?