* Bus between CPU and South Bridge not protected.
* Most of Intel's "secure boot" functionally implemented
in South Bridge.
* At boot time, CPU asks South Bridge ... whether it needs
to secure boot.
* TPM chip connected to CPU through insecure LPC bus. Any TPM
measurement can be forged.
Maybe they meant 'current' when the Xbox One was being designed?Edit: at about 40:30 they say, 'a lot of this is still true'.