Disabling Verified Boot and not having Google Play Services would dramatically reduce the security posture of an Android device.
Disclaimer: I work at Google.
Disclaimer: I work at Google.
I understand Verified Boot, but how would removing Google Play Services damage security? It would seem to reduce the attack surface.
source: im another google engineer
How do you propose a custom rom can establish hardware root of trust without being signed by the device manufacturer?