289
Apple already shipped attestation on the web, and we barely noticed
(httptoolkit.com)
This is a most excellent place for technology news and articles.
It needs integration with the TPM/secure element chip in the CPU and a device key issued by the manufacturer to sign an attestation that nothing in the software chain from kernel to browser has been modified .
These schemes tends to get regularly broken, just look at SGX