Earlier quoted context omitted.
Just wait until they go full 'treacherous computing' and turn on remote attestation using TPMs.
Remote attestations already exist with SafetyNet, but don't use TPMs (IIRC). TPMs are interesting because they allow local attestations; and it's happening already, for some use cases: https://android-developers.googleblog.com/2017/09/keystore-k...
wow... thanks for the link. I need to keep a closer eye on the platform, apparently.