How so? In my experience, the peak of Device Tree days was with the final 32-bit ARM chips before move to aarch64. Back then you had U-Boot which did minimal stuff and after that the kernel had full ownership of the hardware, no management firmware layers or extra code at runtime.
It's during the move to 64-bit aarch64 where things started to imitate the x86, with more and more always-on firmware and secure monitors and whatever being introduced. Nothing really to do with device tree, in fact ACPI is being pushed to the ARM too, yet again hiding more details of the hardware towards proprietary bytecode.
https://jxself.org/titanic.shtml
He did it well. On "security", the author loves more to own his code/adata than anything. as did the PDP10/ITS hackers.