In an ideal world, all smart cards/TPMs/HSMs would have these two properties:
1. Under no circumstances would they ever be sold with any private keys already on them
2. There would be no way to prove or determine after the fact whether a given key was generated internally or imported from an external source
If those two things were true, then you'd still be able to get 100% of the legitimate security benefit of them, but they'd be completely unusable for DRM and other evil things.
1. Under no circumstances would they ever be sold with any private keys already on them
2. There would be no way to prove or determine after the fact whether a given key was generated internally or imported from an external source
If those two things were true, then you'd still be able to get 100% of the legitimate security benefit of them, but they'd be completely unusable for DRM and other evil things.