In that case, I'd humbly suggest you come to my UEFI talk. I'll be going over the broad strokes of how to setup Secure Boot so that you run the signing authority, not Other People out there somewhere.

I don't care for Secure Boot, I don't think it's something end users will implement well, but there's no reason you can't. Setup local signing keys, import them, and sign your local trusted Grub/rEFInd/other bootloader. If you're wildly independent, sign your distro's kernel binaries and boot them directly. Most kernels have efistub support enabled.

Windows 8 certification required secure boot, but it required a secure
boot that could be disabled. Windows 10 certification requires secure
boot, and is mute on whether or not it should be disableable. So when
you see a computer saying "Windows 10 authorized" or whatever, there's
no guarantee that you can disable the secure boot.

For those of us who use lesser known distros, this is a big problem.

