Traditionally this has been physical possession of the device.
The treacherous computing model is to make the trust root a key that only the manufacturer has.
I'm proposing that the trust root should be "possession of the device for X days", which doesn't privilege the manufacturer with indefinite control over something they've supposedly sold.
I don't understand what you're describing. Things like "2FA" and "notifications" aren't part of a bootloader, and therefore would have to be implemented externally. Keeping the manufacturer as part of the privileged base is still the dark ages.
FWIW the answer to the gifted trojan iPhone is to make the bootloader report the signing key that it is trusting. If you receive an iPhone from someone else and you want to assure integrity, you either plug it into another device of yours which checks the Apple signing key (possibly needing to wait X days to load it), or you bring the device to an Apple store where they do it for you.