It seems to me that the "attestation" doesn't add anything (other than the ability to positively identify a device across multiple sites, which is a downside rather than an advantage) to the TLS session set up process.
If a site (i.e., a corporate VPN) needs to ensure that a particular client is authorized to access it, client certificates and user authentication already provide such confirmation.
I don't see why this is necessary for sites that, while they may wish to encrypt sessions with TLS, don't have any reason to track (and potentially block) devices that don't possess the properties (e.g., no ad blocker) they want to see.
ISTM that this is antithetical to the peer-to-peer nature of the Internet and is just another way to restrict access for those who are deemed to be acting against the financial interests of large corporations.
I have no interest in donating my CPU cycles and bandwidth to those who want to identify/categorize/advertise/restrict my access to the open internet.
This could also kill off tools like curl, yt-dlp and other non-browser tools.
Altogether a terrible idea. Or am I missing something important?