> "Device will refuse to install" is precisely an instance of "security built 
> in at the OS level".

Yes, but that's beside the point; it wasn't the relevant part of the example. 
Any software, privileged or not, can verify the signature and detect whether 
the binary has been modified. That's what the OP wants.

