So why exactly can't they do an OS update with the new signing keys? OEMs put out OS updates all the time. Plus if they don't want to do that, they could update their individual apps to use the v3 signing schema. They've had 6 years to figure this out.