TPM 2.0 includes rate limiting, and in most cases now it is actually an fTPM built into the CPU which is even more secure. This 45 minute brute force attack doesn't work.
Secureboot is not a sandbox. It is a certificate chain that validates that the OS bootloader, kernel, and basic drivers have not been tampered with. Malware used to replace the NTFS drive in Windows so that anti-virus software couldn't delete its files, and it effectively sandboxed the whole OS by controlling what it could see on the disk. That became impossible once Secure Boot was enabled, because the NTFS driver had to be signed with the Microsoft key.
If you care about security, you can use the same measure to make sure your Linux OS hasn't been tampered with. You can load your own key and sign your own kernel too, it's a mandatory requirement of Secure Boot.