Earlier quoted context omitted.
> For devices, direct attestation could authenticate the device making the request (e.g. as a legitimate MacBook Pro, or something). The attacker may well be using a MacBook Pro, a real one. With a TPM.
I think the only MacBook Pros with real TPMs were the 1, and 2, series from 2006/2007. Right now Apple don't allow you to do device identity attestation with the secure element. But in the world where you take this approach you don't just tie issuance to "I have a hardware keystore", you tie it to "This hardware keystore has an identity that I know belongs to a computer I own"
Both devices might be very pricey, real, up-to-date machines with TPM and keys and everything you want. The problem is that you can't tell whether the TV is the one TV that the iPhone's owner means to sign in.