Indeed. "turn this key to automatically certify the next thing that boots" would be fine -- and I strongly suspect that if that was the mechanism, people *wouldn't* accept machines that where sold without keys, and for which MS and others hold keys, but where the owner does NOT get keys.