It’s less about a "scan" and more about the "handshake." Look at things like Windows 11 requiring a TPM and Secure Boot, or the Microsoft Pluton chip being baked into newer CPUs.
They don't need to inspect your code. They just need a cryptographic "attestation" that says your hardware and kernel are in a "known good" state. If your DIY kernel doesn't have the right digital signature from the manufacturer, the service whether it's a bank or a Netflix stream, simply says "computer says no" and denies the connection.
Sure, we'll find workarounds, but for 99% of people, that "invisible border" is a brick wall.
You’re right that the average person doesn't care about fingerprinting, but that’s exactly the problem. To me, browser fingerprinting isn't just a technical quirk, it’s a violation of privacy that effectively erases your ability to be anonymous, regardless of whether you have a VPN or not.
If we let OS-level ID checks become the standard because people don't care, we’re essentially legitimising that tracking. My red line isn't just a government log of my identity, it’s the fact that the tech is being built to make that log possible in the first place. Once the infrastructure is there, the incidental proof of identity quickly becomes the primary feature.