Then all they need to do is require that ISPs only allow packets to be sent by computers that have passed a Measured/Trusted Boot check, and suddenly all online activity is restricted to "approved" computers, running code from "approved" app stores.
"One Ring to rule them all, One Ring to find them, One Ring to bring them all and in the darkness bind them."