Earlier quoted context omitted.
I'm seconding the Pixels - they're also pretty much the only phones that allow you to upload your own signing keys, so you can run Google-free GrapheneOS with secure boot enabled. (Which is also nice for long term support.)
I have been nominated seven straight years for hacker news reader with the least knowledge of security, so I’m embarrassed to ask: what keys would one want to sign and why?
Essentially the same way UEFI secure boot works in the PC world.
You’re telling the device hardware “it’s only ok to run software that’s been signed with the private key that matches this public key”, so that once you’ve done that, you can have confidence that the operating system hasn’t been modified in future by anyone other than the original vendor (as only they have the private key).