lol, another plaintext file is what looks like the src for the firmware signer for this TPM, with three ECC private keys hardcoded (two are commented out)

there's also the code for the firmware flasher on the device side, and binary for the util that talks to that code, with identical hardcoded key+iv for crypting the buffer transferred over uart (it's china, so as you'd expect the algorithm is SM4-CFB)
0

If you have a fediverse account, you can quote this note from your own instance. Search https://labyrinth.zone/objects/edd7dc37-2d53-4f64-8bfe-67ffc9424d30 on your instance and quote it. (Note that quoting is not supported in Mastodon.)