Because almost no vendor wants to give you the keys to your system voluntarily. If secure boot puts the users in charge, I'm all for it. But there are forces at work to subvert the system to achieve a better vendor lock-in. And providing them with better means to that end is unethical.
You know that this feature only works because Microsoft added it to the requirements of the Windows Logo program for x86 based computers almost at the last minute. Mainboard manufacturers would otherwise cut corners and add the MS signing key as the only unchangeable key to the system.
At the same time, MS specified for ARM computers that want to run Windows that the key must be fixed and irreplaceable.