And what security value does that provide, when millions of attestation-passing devices have public unpatched LPE vulnerabilities? Anyone can get one and run arbitrary code on it as root. It's completely worthless for actual security. Worse, it does the opposite, because a newer third party ROM that patches those vulnerabilities would fail attestation, preventing honest users from updating their device and thereby leaving them vulnerable.
What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.
What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.