The only alternative is complete lockout and walled garden, thankfully Google didn't go that route in this case.
Reflashing the boot firmware was not really an option back when I checked.
No, that's an imaginary problem invented to rationalize this bullshit.
I don't think there actually exist people so ignorant to not realize that buying used hardware comes with caveats and that you usually get what you paid for.
A company I worked for decided to settle after someone broke in, stuck something in the safety switch and got injured while illegaly operating a machine we had made.
The reasons were simple:
1. There were no sticker saying this was bad. (But as mentioned we had other safety measures that were deliberately overridden.)
2. While we had a fair chance of winning the costs and risks were simply not worth it.
Lessons learned: if something goes to the US, make sure the stickers are in place.
The reasons were simple:
1. There were no sticker saying this was bad.
And this shows that if Deere cared about liability and not about ripping customers off every time they need to repair something, they would use stickers instead of DRM.
And you can laugh at safety stickers, but IMO they are a good thing. They mean that your responsibility is limited to providing basic safety interlocks sufficient for the intended use and informing what is and what isn't intended use. Everything else is user's problem, as it should be. I certainly prefer this over wasting manufacturers' time on elaborate idiot-proofing and then later wasting hackers' time on breaking it.
If JD had a reasonable port to the flash, it would be easy to read it out and see if your phone (or whatever) thought it had the correct image.