Meanwhile, on my linux PC with full root access, because I am the admin, this somehow isn't an issue. No, attestation is not needed. It never was before, and it still isn't, especially because it is NOT required on systems that have way more chance of being set up insecurely. There's nothing stopping me from viewing the source code of the page. There is nothing stopping me from taking a screenshot. There is nothing stopping me from doing anything. I am root on my machine, and that's ok there. Why is remote attestation required? Why the hell would I even want google to "vouch for me" as a european?