I get the feeling that dep8 is pushed out to devices, rather than having the firmware available for download.
I think that's how the security was compromised previously... someone dug through the firmware.
It makes sense to me... This reduces the attack surface to a random small window of time when the firmware is pushed out.
Clever.
I'm just guessing. It's a shame there is so much hush!