I have explained my reasons multiple times. Amber/citrine/pokey are a model where the android OS is the host OS, notedeck is cross-platform, so having these features in the virtual machine makes things more consistent and portable across platforms.
The amount of armchair engineers telling me how to engineer this new system is wild. They think i can’t make it secure either, like somehow rawdogging it into amber will be more secure than a properly engineered signer enclave in the virtual machine separated from the micro apps.
Granted i still need to implement this since we don’t have any untrusted apps, but it won’t be any less secure than amber.