• There’s no downside to having it.

    Sure there are. If it gets compromised with malicious code, I have no way of removing it.

    I can protect ring 0. I can keep crap out of ring 0. If all else fails, I can nuke everything in ring 0 and boot a fresh OS installation. But I can’t do a single bleeping thing except throw out the whole machine if malware takes over ring -1.