Hacker News new | ask | show | jobs
by yjftsjthsd-h 3123 days ago
Well... yeah? They're the OS vendor; there is literally no way for them to do their job without having the ability to update the system.
1 comments

Yes they have to be able to update the system but in this case they are also able to update the firmware without asking which means anyone who can impersonate or coerce them can also update the firmware.
If you control the OS, you also control the firmware (if you want a way to install new firmware from the OS). No way around.