"Hardware-based attestation
GrapheneOS provides our Auditor app for using a combination of the verified boot and attestation features to verify that the hardware, firmware and operating system are genuine along with providing other useful data from the hardware and operating system.
Since the purpose of Auditor is to obtain information about the device without trusting it to be honest, results aren't shown on the device being verified. You need a 2nd Android device running Auditor for local QR code based verification. You can also use our optional device integrity monitoring service for automatic scheduled verifications with support for email alerts."
When it says u need a 2nd android device running Auditor because it doesn't trust the pixel for being honest, wouldn't this same principle apply to the 2nd android device for the local QR code based verification?
Seems like it would only be as good as the weakest link and I don't have a second android device I trust when it comes to the step.
Also it mentions Verified Boot and Attestation features that Auditor uses.
If Auditor needs those two can I just check the integrity with both of this things one being the built in attestation feature by the GrapheneOS pixel?
Or does the firmware, hardware and operating system have to be checked by a different source like what Auditor would be doing?