and websites can check the attestation on the registration to make sure it came from an apple/infineon/titan TPM