Possible PureOS (security) future?

The fundamental point for #2 (SecureBoot) is that it is only as secure as Microsoft is.

That’s false: Purism utilizes SecureBoot without relying on MS for anything. See https://docs.puri.sm/PureBoot.html for implementation details.