treyd parent
Secure Boot (or whatever it's called on each hardware platform) relies on trusted cryptographic keys to sign "the next step" in the boot chain, all the way back to the bootrom. This is how the higher-level SafetyNet attestations work on Android, and equivalent features on iOS, XBONE, etc.