Conversation

This is just one example. There are other ways it is approached. It is also part of how they make their laptops. So, if the firmware has signature verification, they'll block updating it somehow. If it doesn't, it'll still end up being blocked since components lack open firmware.
1
So, exactly what I said: blocking the ability to ship firmware updates, but not necessarily going out of the way to stop there being any way to do it if it isn't required to block updating it from the OS. They HAVE blocked "out-of-band" updates to accomplish their main goal.
2