The basic fact is that Microsoft drives the desktop x86 PC market.
Nobody else has the power they do, and that isn't going to change any
time soon.  They are creating the two classes you describe.  The
hardware is coming (like it or not), and Fedora can either change to
deal with it or not.

If Fedora does nothing different than is being done today with F17, it
will always be in the second class, requiring the user to disable secure
boot.  Even getting to the point where the user can generate/install
their own key requires more work.

Once the work has been done to support signing with a user-generated
key, it isn't that much more of a step to get the Fedora-provided
binaries signed with a key that allows the distribution to step up to
your first class, where it will load easily on systems.

