The articles doesn't say, but this would require an TPM in the machine to be successful.. right?

Without a TPM how can the EFI be trusted? You just have to replace it as well as the boot loader and kernel.

