Yes, I know that it only fixes things going forward, and I know that the answer to any question that starts with “why don’t they” is “money”.
Sigh.
Yes, I know that it only fixes things going forward, and I know that the answer to any question that starts with “why don’t they” is “money”.
Sigh.
More likely "trust". A purpose build instruction with a black box implementation on hardware that has its own hidden OS with direct access to the network is one issue. The fact that Intels CPUs are a bug riddled mess that have been a significant headache to anyone caring about kernel and application layer security is another. Who needs security if disabling all the mitigations makes you look great on benchmarks.
And we trust purpose built security hardware all the time; think crypto accelerator cards and HSMs.
CONFIG_RANDOM_TRUST_BOOTLOADER=y
CONFIG_HW_RANDOM=y
CONFIG_HW_RANDOM_TPM=y
and so forth all exist.