Earlier quoted context omitted.
> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.
> AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. For now.
I wrote about this nearly a decade ago:
https://www.theregister.com/2013/11/14/microsoft_surface_rt_...
AFAIK, rather than make the firmware unlockable, MS sent vast amounts of inventory to landfill.