It is still a complete disaster. Nobody needs the password to your bootloader when it can access all your data through your web browser.
https://en.wikipedia.org/wiki/Trusted_Platform_Module#Field_...
For ASIC-only devices, the keys are burned-in, which is user-hostile too.
It is still a complete disaster. Nobody needs the password to your bootloader when it can access all your data through your web browser.