Ability to root and sideloading are two different but similar issues on the topic of freedom.
wait what? It's basically the most used/desired tablet, afaik, at least in Canada/US
And of course forget about anything that isn't iOS or Android. I don't expect banks to support alternative OSes anytime soon.
I probably won't root my next phone, not worth the hassle for a daily driver.
What could be nice is if phones could run VMs, so you have your stock ROM with all your "important" apps, and a VM where you can run anything you want: hacked Android, Linux, maybe even a desktop OS. Modern phone hardware should be more than powerful enough to do that.
The easiest daily driver to root is Sony and Google phones. You simply unlock the bootloader and flash. There's no nonsense to deal with.
That said, they have locked bootloaders on some devices. Predominantly in the US market, I believe at the request of carriers. However, it's traditionally been the minority of devices.
Kiss some multimedia apps, payment apps, and enterprise security features goodbye...along with a bunch of random features like private mode in their browser.
Samsung at least don't require personal details for you to take control of your device. Sure, you lose access to some multimedia, but don't blame Samsung for that, blame Widevine DRM certification. Knox goes out the window, but the entire point of Knox is to (try) guarantee a device isn't tampered with. At least you can remove it!
I would consider a device tampered with if someone besides me (the owner) did something with it, without my authorization. But anything short of that is surely just me using the device. I mean, I have physical possession after all.
It's like your laptop's motherboard detected you installed another OS in place of the OEM-provided Windows installation, and overvoltaged your NVidia GPU to burn it out. "We have every right to not support high-performance graphics on any other OS other than our own - if you want to install your own OS, you can still use the integrated Intel GPU".
In other words: there's no way for me to just take the phone to my workshop / local hackerspace, and fix it with a soldering iron. Even if I could source the right parts, it's going to be a PITA to make them work. I didn't investigate it further, but I assume that these days, cryptography is used for critical parts to attest each other as genuine (similar to what new iPhones do, which is why you can't just replace the "home" button if it breaks).
Additionally, since I haven't heard of people doing software workarounds, whatever in Knox is reading the state of the eFuse, cannot be trivially patched. I recall reading somewhere that triggering the eFuse somehow overwrites Knox itself - if that's correct, then they may not even be anything left to enable afterwards.
----
I'm going to concede here that my example was somewhat hyperbolic - burning a single eFuse isn't the same as overvolting the whole GPU. But only somewhat - the reasoning/intent behind the two cases is the same. Additionally, cryptography blurs the line between what's hardware damage and what's a software limitation. Take, for example, secure erasure of data: you can smash a hard drive with a sledgehammer and then microwave the remains to slag, but you can get the same result by keeping the data encrypted, and then... losing the keys.
Would I like to have an unlocked bootloader? Sure. Is having a locked bootloader equivalent to only being allowed to install Apple approved apps? Of course not.