This will be mostly rambling disguised as a technical walkthrough. I will touch on certain topics such as hardware roots of trust, signed image formats, Qualcomm boot stages, Android Verified Boot, UEFI, measured boot, and remote evidence (remote attestation). My idea is that I will briefly introduce the concepts and then introduce a seemingly perfect-world-example that can still break under certain assumptions. So, expect a technical post leaning towards offensive security.