The article says the manufacturer has a copy of all the preloaded keys for TPM chips. So that might be a wee bit compromising.
If Dell/HP/IBM/Lenovo are deliberately hashing their TPMs prior to distribution, then they’re not true TPMs. I have a v2.2 TPM from Infineon. The hash was created when the TPM was first plugged in and is based on the unique nature of the hardware in my machine. That’s how a TPM hash is generated.