> The whole project isn't targeted at end-users. It's IoT, businesses, hospitals, government agencies, utility companies, etc.
> It's the security needs of these organisations that are addressed by this technology, not yours, not mine.
It's perfectly fine to let a sysadmin lock down a computer to reduce what the end user can do.
None of these use cases or security benefits require taking power away from the sysadmin. And that's what the argument is about: not whether the end-user is losing control, but whether the sysadmin is losing control. With the obvious note that lots of home users are their own sysadmins.
> I see this chip in the same area as Intel's vPro, TPM 2.0, AMDs ASP (in their Ryzen PRO line), and so on; not necessarily aimed at end users (aside from the occasional buzzword) and more aimed towards businesses and government users (as part of their Zero-Trust initiative).
Those are basically fine, as long as they can be disabled when not needed.
But if I'm forced to give someone else special beyond-root access to my device for DRM purposes, that's not acceptable.