I am sure they are not guessing, and know well enough who uses the backdoor access, and how often, because they are doing the same. Of course, they are not going to present it all to lowly so-called citizens, so you only get the final decision that the dangers were considered greater than the benefits, and some media-friendly hand-waving. It's also a clear signal for other companies that “extended cooperation” is the requirement of commercial success.
When those responsible for “security” actually depend on countless things being insecure crap, we will never see any real change in how things are done, only the talks about never-ending work done ad infinitum. Cheaply and insecurely made device benefits not only its maker that saves money on development, it also benefits most of those who are supposed to check them, and set better rules for them. Instead, we have various “IoT security teams”. It's like starting the fire at an oil refinery, and then announcing that you need something more than a couple of fire trucks.
When those responsible for “security” actually depend on countless things being insecure crap, we will never see any real change in how things are done, only the talks about never-ending work done ad infinitum. Cheaply and insecurely made device benefits not only its maker that saves money on development, it also benefits most of those who are supposed to check them, and set better rules for them. Instead, we have various “IoT security teams”. It's like starting the fire at an oil refinery, and then announcing that you need something more than a couple of fire trucks.