Earlier quoted context omitted.
> And they are implemented using all the evil things like Secure Boot, TPM, and Pluton. There is nothing evil with TPM when you fully control it. See: Librem Key.
You either don't remember or wasn't there when TPMs were first talked about, in either case I envy you then. And yes, there's nothing evil involved if they are owner controlled, something that honestly was heavily Microsoft pushed because they do have clients that insist on them - the DRM functionality in intel ME has keys controlled by broadcasting associations instead (this is why you can't stream HQ on Linux from…
Have you seen OCP's Caliptra RoT, which requires OSS firmware, enforced by dual-signing of firmware by both OEM and owner? Currently for hyper-scalers, but this approach can be adopted by other enterprise customers, https://www.youtube.com/watch?v=p9PlCm4tLb8. Attestation will be done to Caliptra, which can then release SoC boot ROM from reset.