Why is a Yubikey more trustworthy? You don't have the source code, you don't have the hardware design. In addition, a Yubikey is given no information about the system boot state, so is in no position to identify that the system has been tampered with.