We need a hardware attestation vendor who isn’t also selling ads on the same device. Something like, I dunno, an identity module which you could maybe insert into the phone?
We never had one on desktop; no real issues. Hardware attestation is primarily in the interest of the vendor, not the user. The user relies on chains of trust. This is how the world works.
My worry is one fine day Microsoft, Samsung Apple, and Google (rest of SV Media companies like Netflix etc) will join hands in bringing security and force a ChromeOS or macOS type totally- we decide everything for you.
With Nitrokey's open source firmware plus quite a bit CS education (specializing on cryptography) you can check whether their implementation quality is good. However, that is a lot of effort which will probably result in also requiring a third party certification.