OTAConfigNoZeroTouchPrebuilt is an app on Pixels that checks for a carrier lock. When a Pixel first connects to the internet, this system app will immediately check if the device is carrier locked. If it’s not or is locked to a carrier that doesn’t restrict unlocking, it will retrieve a token from Google’s servers which will allow bootloader unlocks. If the token cannot be received, then the bootloader cannot be unlocked. This means if Google’s servers ever go down, you will not be able to unlock your Pixel’s bootloader, as it won’t have the token.
Mostly because unlocking the bootloader and rooting my Pixel 9 Pro was the very first thing I did to it before installing my SIM card (yes, I still use a physical one). I also skipped the wifi setup.
The GrapheneOS factory images flash a non-stock Android Verified Boot key which needs to be erased to fully revert back to a stock device state. Before flashing the stock factory images and before locking the bootloader, you should erase the custom Android Verified Boot key to untrust it
Would love if someone could fully confirm, though.
I find this blurb on Pixels interesting:
Mostly because unlocking the bootloader and rooting my Pixel 9 Pro was the very first thing I did to it before installing my SIM card (yes, I still use a physical one). I also skipped the wifi setup.
Edit: in all seriousness, this is a handy list.
Does this still apply after installing GrapheneOS and locking the bootloader again?
I think it does not apply since the verified boot key is replaced.
This thread seems to back this theory up: https://discuss.grapheneos.org/d/444-how-do-i-unlock-the-bootloader-in-grapheneos/3
Would love if someone could fully confirm, though.
Thanks for sleuthing. Appreciated.