"How about running the core OS on read-only memory"

Then you're completely screwed when you need to patch a security bug in your OS. The whole point of this root-of-trust thing is to be able to install trusted updates. And there will be bugs.


