I don't think it matters whether Chrome can add keys to TPM/Secure Enclave (as the article argues) or if it can only read the keys already in TPM/Secure Enclave (as you argue). In my understanding: both ways the key (either new or existing) could be attributed to the hardware owner, and not even an OS reinstall will help. Hence, my question.