Dumdum
This makes a lot of sense.
When I booted into the OS after removing the key, it mentioned only that the bootloader was unlocked (required to remove the key) but nothing else.
Would there be some way in the OS to tell if the system is still verified with the secure boot key?
I also wanted to ask, when flashing a new ROM or stock ROM over GrapheneOS--without removing the GrapheneOS verified boot public key, will that key remain the same and unused in those ROMs? And when flashing GrapheneOS again, I assume the old key left behind will be overwritten with a new key? It seems that the key is set under the variable name avb_custom_key
, so I'm wondering about the interaction with other ROMs/stock if not removed.