One of those primary keys is the Endorsement Key (EK). The EK is generally certified by the TPM vendor, and they include that certificate in the TPM.
You can generate your own EKs and certify them. All you need to trust them is: a computer, a TPM chip you trust is legit (probably because you validated its factory EKcert), and physical security while extracting the public key of your EK'.
> If any particular manufacturer would give you the option to just buy the keypair or make it possible to dump it somehow, they would surely get blacklisted.
Yes, well, Internet-scale security (e.g., TLS) relies on the reputation of trusted third parties. The problem is that the too-big-to-fail phenomenon applies here too: what are you gonna do, stop using the one CA everyone uses, the three or four browsers everyone uses, the three OSes everyone uses?
> This whole "trusted computing" thing is treachery to the highest degree.
Oh, it's hard.
The lack of end-to-end security between the CPU and the TPM is pretty nasty. The solution is to use an on-CPU/ME firmware TPM that runs in the ME or in a secure enclave like solution -- no bus to tap there!
But even then, there's just no way to attest to the security of a long-running host. Yes, there's things like dynamic root of trust measurement, but by and large it's hard even to establish what would be a trusted state since, among other things, there's no authoritative list of trusted firmware ROMs or anything like that.
And, oh, right, you meant far beyond the realm of TPMs. Yes, "trust" is really weak.