> I wouldn't say it's a solved problem. Just have to find an exploit that works with verified / attested boot
In general though on devices that are rootable, white-hat hackers are more inclined to responsibly disclose vulnerabilities instead of releasing them as a way to root said device. So having a rootable phone does increase security.
What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
The thing is, the whole topic is not fully binary. I agree with you that having a rootable phone does increase security in certain ways.
> What doesn't increase security is when bank apps that are essential to daily life start detecting that a device has been rooted and force a lot of people into using closed source extensions to hide the fact that the devices is rooted.
I'll ask naively: Why not? I can come up with a bunch of arguments why it does help the bank and why it might reduce the risk of certain attacks.