> First, that when some malware gets in, it looks like you.
I don't see what this has to do with trust. Whether or not there is a secure trust chain, malware can likely impersonate you.
> Second, that people who are not technically savvy will not be able to use that control to protect themselves, but will instead very often have it used against them.
If people are going to ignore the flashing red banners that pop up when they try to override the trust store that comes with their device, then that is a price we have to pay, IMO. We accept in the rest of our lives that some things are dangerous, and while we erect many barriers to make those things more difficult, we recognize that is the price of freedom. People will do them anyway, and some will be harmed. It doesn't have to be frictionless, it just has to be possible.
Is there a spate of malware going around that involves users installing new keys in their UEFI secure boot trust store? I haven't really heard of this. I also haven't really heard of a spate of malware using Android's developer mode that is pretty easy to enable, if you know how. I think the risk involved in giving users ultimate control of the device's trust store is greatly overblown.