I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg
RMS must be having daily nightmares at this point.
P.S.: Fantastic talk you linked there.
Doesn't sound like it's engineering-driven, even though they still do have a lot of capable engineers sitting there and atrophying.
I also wouldn't rule out that the less capable ones actually believed that the systems they've built are unrootable or something like that.