Custom ROMs have had just about enough of being Android's second-class citizens
androidauthority.com
androidauthority.com
On older devices, the remote attestation feature can be software-only, and that's easily faked. Newer devices support hardware-based attestation, which is not. A significant number of third-party apps refuse to run on devices that do not attestation, something Google makes no attempt to discourage. If you recall an uproar from the tech world when Microsoft was trying to push something called "trusted computing", this is the same kind of thing.
In the Mastodon thread, GrapheneOS asserts that many OEM Android ROMs do not actually meet CTS security standards while GrapheneOS does.
GrapheneOS supports the hardware-based attestation mechanism so that devices can prove they are running unmodified GrapheneOS, but apps using Google's attestation service will not accept that. GrapheneOS wants Google's mechanism opened to third parties provided they meet the same security standards.
One might describe that situation as Google using market power to exclude competitors, which is illegal.
https://grapheneos.org/articles/attestation-compatibility-gu...