Earlier quoted context omitted.
Has TPM been a net positive or negative for users / enterprises / the industry?
TPM protects against two main threat models: 1. You don't trust people with physical access to the computer. For the average home user, this means you consider the hardware owner a threat. 2. You want to protect against malware that has already taken complete control over the OS at runtime, and that wants to write itself to disk or the BIOS so that it survives a reboot. At this point, the attacker has already won, so…
I guess you’re looking at it as a freedom for gramps to dual boot a homebrew OS, and I’m looking at it as taking away gramps’ freedom to install persistent malware that requires buying new hardware to get rid of.