b) If you have physical layer access, you can override any security settings. Gatekeeper et al cannot change this fact. You will be able to write/run code, just not necessarily distribute it.
That is not necessarily true. It is a "simple"[1] matter to have non-overridable security programming arbitrarily close to core hardware, from a chip on the motherboard to etched directly into the same silicon as the processor or BIOS. This isn't just a theoretical concern: plans to do this are already underway, see http://en.wikipedia.org/wiki/UEFI#Secure_Boot
[1]: By "simple" I mean the concept is simple, the implementation is plenty complicated.
That is not necessarily true. It is a "simple"[1] matter to have non-overridable security programming arbitrarily close to core hardware, from a chip on the motherboard to etched directly into the same silicon as the processor or BIOS. This isn't just a theoretical concern: plans to do this are already underway, see http://en.wikipedia.org/wiki/UEFI#Secure_Boot
[1]: By "simple" I mean the concept is simple, the implementation is plenty complicated.