While I can be as paranoid as the next guy, the article states:
Secure boot is designed to protect against malware code running before the operating system. This isn't a hypothetical threat. Pre-boot malware exists in the wild, and some of it is nastier than you expect. So obviously bootloaders need to be signed, since otherwise you'd just replace the signed bootloader with an unsigned one that installed malware and booted your OS.
The ‘Flame’ stuff scared me. Since I’m not doing IT 24/7 like I used to, am I going to be able to easily get boxes that aren’t Microsoft signed, or will you be forced to pay a $99 Microsoft tax every time you reconfigure a box?