@carcosa if that's the case (I haven't done a full technical analysis of what they propose): I think that's a fair criticism, and I don't think a spec proposal should be accepted when it's not self-consistent.
I think that's significantly more nuanced and actionable commentary than "DRM bad", and I presume that this is part of what the spec review process would go into (W3C/Whatwg/... have privacy experts reviewing these things, and they seem to already have been engaged).
@delroth Yeah. Specifically, look at the discussions of the holdback mechanism, which is the one part that is supposed to prevent website operators from discriminating against unattestable browsers. Stakeholders in the security business are arguing that it's not acceptable to have holdbacks at all; I'm arguing that if implemented, holdbacks will erode over time until attestation can be used to discriminate on the basis of browser/plugins/etc.