Then what's the point of things like passwords and fingerprint scanners?
> Having the computer be able to attest that it's unmodified means that it doesn't have to mistrust you so aggressively, relative to today.
How so?
> Requiring a reboot to rescue mode to disable SIP is sufficient to block most social engineering attacks that would otherwise have you click through dialogs to bypass it. A dedicated attacker can still overcome this, and once they do, they can impersonate you readily.
We need to lock people out of their own computers to protect them from social engineering?
> I don't think most websites will bother, but those that care sure would love to be able to do so.
In practice, this will end up just like the abomination that is SafetyNet on Android, where if you take control of your own device, you can't use Netflix, Snapchat, Pokemon Go, Super Mario Run, Android Pay, etc.
> keeping their system in secure mode
Really? "secure mode"? What kind of attacks specifically would this prevent that an IT department would care about, as opposed to Hollywood/RIAA/etc. caring about?