I've replaced all my GPT disklabels with Sun disklabels because I refuse to let them talk.
UEFI still boots. Spec said it can boot from fat in an eltorito floppy image and sun disklabels sit in the second or so sector. Spec also said it abstracts the type of volume so all boot methods always work for all drives. ISO images don't use the first 4kB so it doesn't see there's disklabel at all
So now I can mount the ssd as iso9660 but there's also partitions on it of which the third spans the entire drive (of course, because that's the c partition)
This is pretty advanced, and who knows if anybody else is doing it exactly like this or not, but it is exactly what the hardware is supposed to be easily capable of, just as easily as what the vast mainstream users are getting out of the hardware by "default".
This type versatile performance is built-in just like the mainstream arrangement is built-in, the thing is you have to figure it out for yourself through the complex web of capabilities that have been long bypassed in order to make the default experience seem like it is actually simpler or more reliable, when it is not.
Not neccesarily a guise of security, but perhaps a different means of security. E.g. securing stock investments, profits, monies, etc. Nothing is 100% secure, you can't be in the void and still call it a void, etc
iiuc the OG Verizon Pixel has an unlockable bootloader, but the operating system doesn't let you unlock it, meaning root access should allow unlocking the bootloader.
some devices have a legitimately locked bootloader, which means you're SOL.
There are privilege escalation CVEs in bootloader code too. I remember unlocking some very early locked bootloaders this way in the early days of android.