And if attestations are rate limited then a grace period until they can get enough attempts in to be confident.
If sites are expected to accept opted-out clients because they might just be randomly non-attested, why wouldn't the hackers and fraudsters just opt out of attestation?
This past year in particular has really hammered it in for me that even if you can never truly delete something from the internet, it doesn't mean it'll still be there when you're looking for it. Saving a link to something is not saving it at all, and I'm starting to become a data hoarder.