Earlier quoted context omitted.
From their Twitter page Fun fact: We actually had an EFI payload. We just had issues with the installer and it was left unadded.
And all of it just because they didn’t have a Windows 10 VM. Would’ve been funny to see what they’d have done with EFI – maybe a graphical message? Anyway, the only way to solve these issues in the long-term is with relying more on signed software, similar to how Linux repos work already today.
It seemed as though Windows was warning the users that the software was unsigned; they just clicked through it. That's a different problem -- it's entirely possible to have a signing system, but if enough developers hate and refuse to use it, then users will quickly become conditioned to click through the warnings.
I'll be honest: if there was an app that I wanted to install, and I got an unsigned-package warning, my first thought on both Mac and Windows would be that the developer probably had an ethical or financial problem with the signing scheme, not that the package was compromised. On Linux, I'd be more confident and probably stop what I was doing, but only because very little software makes it onto distribution systems if the developer has an issue with the platform...