If a laptop is shipped with a Linux distribution, it should only trust the key for that specific Linux distribution by default. Same thing applies to Windows. Having whole bunch of trusted parties by default and all kinds of trivial bypasses SHOULD get fixed along with the rest.