Near 100%. If you look at the binwalk output in his later posts you can clearly see certificates as one of the first things in the binary. I’ll be shocked if this guy ever actually gets his own firmware to run here.
Assuming that the platform is even secure boot capable, you'd blow a fuse or similar at the factory to put it into production mode.
However even then, secure boot isn't infallible. Either they're implemented shoddily, or you end up power glitching past verification.
(I've seen a certain vendor who's name starts with Qualco... fail because they didn't remember that u-boot was... configurable.)