It still baffles me that the official response from the IOTA foundation is that the vulnerability was inserted intentionally as copy-protection.
And even more baffling that their flagship partner Bosch does not seem to have problem with this practice.