You wrote:
> completely insecure if you are not the only one with the key
What key is shared between you and the manufacturer here? There's signing keys and there's passcodes, which ones are you "not the only one with"?
because you don't even have the key? not sure where passcodes came from
This implies you are referring to a key that the user has.
What key does the user have?
A passcode? Password?