This is not the first case of accidental reuse of example keys in firmware signing, https://kb.cert.org/vuls/id/455367 Would it be useful to have a public list of all example keys that could be accidentally used, which could be CI/CD tested on all publicly released firmware and microcode updates? If there was a public test suite, Linux fwupd and Windows Update could use it for binary screening before new firmware upd…
Plus it would only help with that one issue, not with the millions of other ways things can go wrong. Vendors publishing their security architecture so others can convince themselves that it is in fact secure would be better, it is how TLS or WPA get enough eyeballs.