Yes the anti-counterfeit is primarily app enforced (though entirely offline). I do use the firmware encryption features of the ESP32-S3, whatever that is worth, and the firmware is tied to the HSM.
Oh good, you're not pulling a Cricut where the app interactively proves to the cutter that it has an AES key and then encrypts all the G-code with it before transmitting over Bluetooth.
Right?
What happens when app is outdated and can't be installed to current android os?