There is also the option of enrolling your own certs and resigning the bootloader and any Option ROMs you need, if you're really worried / expect to actually be broken by this.
I have a HP BIOS that doesn't go into setup mode (required to enroll certs) so I have no choice but to deal with the MS shim.
Re-signing option ROMs is not trivial (or, well, it's easy to do the signing, it's not necessarily easy to flash that driver back into the card)