you can keep verified boot on custom roms.
play services expose you to googles nsa'd taps we'll hear about in 5y.
source: im another google engineer
source: im another google engineer
How do you propose a custom rom can establish hardware root of trust without being signed by the device manufacturer?