> Presumably that initial firmware must not contain any GPLv3 components?
From "A Quick Guide to GPLv3"[1]:
"Distributors are still allowed to use cryptographic keys for any purpose, and they'll only be required to disclose a key if you need it to modify GPLed software on the device they gave you."
So presumably if the person denies receiving the device and demands a refund, giving up their right to it, then the GPLv3 doesn't require you to give them the key?