Isn't it obvious that the solution is to decouple the software from the manufacturer? They have every incentive to not let old devices be used, even though it works just fine for old-school computers.
The hard problem is not even necessarily building android, the hard problem is afaik the custom firmwares needing a very specific kernel version to work with and having security issues of their own.
If you then want to decouple software completly form any hardware chip it get's complicated fast, are usb ICs software?
Do all ic manufactures now need to hire external companies for their firmware?