Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
(www.welivesecurity.com)
I get why you'd dislike that wording, but this is also how all certificate stores work, regardless of whether we're talking Secure Boot, Windows or Linux. Gotta trust the top level as providing legitimate certificates to then trust everything underlying as coming from the correct parties.
Certificate are something I work with constantly at work and I fucking hate resolving issues with them lol.