The premise is not that it couldn't be faked. It would be more practical to remove the key from the hardware and just use it to sign images if you wanted to do that.
The idea is that a centralized source of trust would revoke certificates belonging to bad actors or those that were stolen.