In future versions once SGX is available (>= Intel Skylake)? Good luck extracting data from an encrypted enclave. This is, after all, the intended purpose[1] for SGX - to create the "trusted computing" (DRM) that Microsoft has wanted for the last decade[2]. It's not like these new instructions are for the end-user; Intel has to authorize[3] you binary before it can be loaded into an enclave.
Anybody using the CDM - even sandboxed - is helping to create that future. If this isn't fought and rejected now, yet another battle in the War On General Purpose Computers will be lost.
[1] https://software.intel.com/en-us/blogs/2013/09/26/protecting...
[2] "Palladium" / "Next-Generation Secure Computing Base" in the early 2000s
[3] https://jbeekman.nl/blog/2015/10/intel-has-full-control-over...