device attestation should not exist, it is that simple 
like if I want my computer to lie to a server then it should always be possible with no downsides. i dont care about why you think that for Security Reasons companies should be allowed to make that impossible.