(I’ll bite and try to steelman) How does a typical user verify that they are running the intended secure software?
Notice also that remote attestation doesn't enable that. The device can never do that itself since if it was compromised it would just display "attestation passed" on the screen without actually doing it.