The obvious answer to "Does UEFI Secure Boot add any actual security" is "Basically every cache of leaked documents from state-level actors or companies selling shit to them has included discussion of how to circumvent UEFI Secure Boot" and why would they bother if it didn't