For now, until hardware backed attestation becomes properly enforced... Isn't security great
It probably will never be. It just takes one OEM to fuck it up and everyone can use their device ID. That's why hardware backed attestation doesn't work, OnePlus fucked it up and now Magisk can pretend to be that phone and get exempted.
If a Chinese oem loses their keys why not just revoke them?
And cut off the phone from SafetyNet? That would hurt SafetyNet adoption and be bad for Google, which is presumably why they didn't do it for OnePlus.
Interesting, I use OnePlus phones, where can I read more about this?