After hearing some stories from friends who work with microcontrollers IMO the most impressive thing about this is that Oxide were allowed to publish the vulnerability at all
So all of that is an improvement, certainly, but it's still not what we need: the source code to the ROMs. We believe emphatically that we need transparency throughout the stack, down to its lowest levels. We need open ROMs, open FPGAs, open ISAs, open firmware -- not just because it's the right thing to do, but because it will result in more secure and more reliable infrastructure!
[0] https://oxide.computer/blog/rfd-1-requests-for-discussion