move the goal from "attesting your device is secure" to "control where run what".
i couldn't care less if you want to run my app on your smart fridge, all i ask it's secure, and not rooted.
What they propose is preventing you to run an app on a device they don't like.
not the same goal AT ALL.

