Earlier quoted context omitted.
What attestation the website accepts entirely depends on the configuration. There's nothing in the spec that will prevent attestations for Linux computers. Linux already works perfectly fine with secure boot and such, I don't see why a signed bootloader starting a signed attestation engine wouldn't be trusted by third party websites. It'll kill open platforms like the rare open source RISC-V implementations, but for…
> I don't see why a signed bootloader starting a signed attestation engine wouldn't be trusted by third party websites. Do you mean a kind of Linux where root cannot do anything he wants? Like Android?
More secure variants like Android, leveraging SELinux and such, help with sandboxing but I don't think that SELinux is a struct requirement.