> maybe we should have read some of this 3rd party code we bundled
Not really practical though, if you push the thought to its limit. That 3rd party code is literally everything that's not written by you, from firmware to the launch UI. And if you don't push the thought to the limit then there's always that risk leading to the same "maybe we should've read X" if something happens in X. Trusting that others will be good stewards of all that 3rd party stuff is a hard requirement for making progress.
I agree its not practical, but including any 3rd party libraries in your project puts it at real risk of upstream bugs. There needs to be acceptance of this rather than blame culture.
I appreciate what you're saying. Commercial realities are very different to theoretical ideals, and of course you have to draw the boundary of trust somewhere to get anything done.
I don't think anyone is saying it's an app developers responsibility to ensure the user's bootloader is securely implemented.
There is a lot of space between verify everything and trust nothing, and I don't think it's unreasonable to question whether that trust boundary is in the right place.
I also think that the code compiled to produce the binary you ship is a perfectly reasonable place to put that boundary, would you disagree?
I'm sure that within the mobile dev world it is normal, accepted practice to include lots of unseen code. I don't begrudge anyone involve for taking the money and doing what's expected.
But I still think it's a mad way to run a business or community project, and it's worth considering how we got here and whether it really has to be this way.