Google is a step ahead of that, with their device attestation technology. Now apps can make sure they are only running in an approved environment.

This is the inverse of what he's saying. Attestation takes control away from users. Permissions give control to users. The ultimate user control is not using the software at all.

That's what the GP meant, wasn't it? "Good luck with your sandboxing, Google is already a step ahead in this cat-and-mouse game".