Earlier quoted context omitted.
The only BYOD device allowed is Chromebooks with a signed bootloader, aka no developer mode or Crouton.
Unless you modify the hardware, of course. Considering Google has teams designing custom PCBs and even ICs, there's a non-insignificant amount of Google devs who could easily circumvent this entire system.
Even someone with serious hardware-foo would only be able to maybe break the trusted hardware bit (by cloning one device id to another, or emulating a device). They couldn't get round the two factor authentication bit.
I'd say it's still a pretty watertight model.