The good thing however is that on the Surface RT, you have:
- the Secure Boot policy hack, that you can use to get code execution pre-ExitBootServices
- yahallo, which escalates to TrustZone to set SetupMode to true, permanently unlocking the device
- Fusée Gelée: bootrom bug