You're absolutely right, and I use a Pixelbook and an iPad Pro for much the same reason. The cryptographic protections are great. (They'd be even more great if I could blow my own bootrom CA into the fuses.)
The phone-home is the issue, however. I've long understood the issue with certificate validity periods and the tradeoffs between short notAfter/frequent reissue and revocation check intervals.
The side effect is that it functions as telemetry, regardless of what the original intent of OCSP is or was. Additionally, even though the OCSP responses are signed, it's borderline negligent that the OCSP requests themselves aren't encrypted, allowing anyone on the network to see what apps you're launching and when.
Many things function as telemetry, even when not originally intended as so. The intelligence services that spy on everyone they can take advantage of this when and where it occurs, regardless of intent.
It's not worth putting everyone in a society under surveillance to defeat, for example, violent terrorism, and it's not worth putting everyone on a platform under the same surveillance to defeat malware. You throw out the baby with the bathwater when, in your effort to produce a secure platform, you produce a platform that is inherently insecure due to a lack of privacy.
PS: The platforms, even with all of their cryptography, aren't nearly as secure as you'd like them to be: https://www.schneier.com/blog/archives/2020/10/new-report-on...