If physical attacks are not an issue, then why is there no separate ROM on the board that provides vendor PSB configuration instead of burning this info into the CPU? Remote attestation as described by the author of this article would continue to work nicely and securely with an out-of-CPU ROM.
A separate ROM seems to be the obvious solution to me, so either I am missing something, or the second-hand CPU market was (deliberately?) ignored to save the cost of a separate ROM chip.