And the bootloader is now locked down across Samsung's ecosystem, as of this year. Sucks.
If you move to using an unsecured "chinaphone" as an alternative to the big three handset vendors, then it's unlikely they are target devices for the myriad of uncertified ROM's.
I think we are going to need software solutions that can run on major Androdis distributions across the variety of hardware.
I think we're going to need something like UTM or Docker (virtualization or containerization) for running our unsigned Android apps and services, and I don't know how feasible it will be.
I'm even willing to use the web apps or webpages for banking, if the browsers can make the handshakes. I'll forfeit using the bank first party apps, if their websites are full featured.