Earlier quoted context omitted.
None of that would solve the issue. Google can only verify what hardware you're running by sending a packet via ethernet to your device. You control all software running on your device, and can send a spoofed result. If you were crazy, you could even just emulate Google's hardware entirely and proxy all requests to that emulated hardware. Nonetheless, while this guy certainly wouldn't be able to do it, many Google em…
Couldn't they do a chip and pin style hardware solution where a security chip generates a response using a unique secret algorithm?
They're already doing something similar, after all.