-
@co_apprentice @GrapheneOS The bootloader or OTA updater on their own effectively can't. If the user enters the LSKF, it can/will be applied. However, when combined with, e.g., transparency logs in the future, targeted insider attacks on firmware become much harder. Either it's an update for all or none.