Conversation

There's no harm in submissions from devices with the bootloader unlocked and/or not running the stock OS, but the attestation certificate chain won't pass validation and it won't provide the necessary information to expand device support. It's filtered out by my extraction tool.
1
2
I could use the StrongBox Keymaster in addition to the TEE Keymaster as a secondary layer of verification rather than as a replacement. It will depend on how much impact including a secondary certificate chain ends up having on reading the QR codes used for local verification.