Is having preinstalled keys at all. (I'm explicitly not basing MSFT for being the keysigner... that makes sense given the current design)
The assumption is captured in "It is further assumed that key material used for signing code by the OS vendor can reasonably be kept secure (via use of HSM, and similar, where secret key information never leaves the signing hardware) and does not require frequent roll-over."
I'd actually prefer the default be:
1. No Keys included in hardware by default
2. User or OEM manually does something to put device in Setup mode which allows them to install an OS. (It can just be going into BIOS and clicking a setup new OS boot option..).
3. That OS installs the keys it plans to use forever. (these could be from OS vendor or locally generated)
4. Setup mode is automatically disabled at next reboot/shutdown.
The idea that you can set one key in hardware and it shouldn't need to be updated just doesn't make sense to me.