TPM and trusted computing/boot chains are some of the single most important security measures that we’ve had in the last decade. I can agree on the kernel level stuff though that’s a bit bullshit even though I understand why low level access is needed for some anti cheat tasks and DRM prevention. I think there should be APIs provided instead of having to install unknown modules