Devil's advocate: assuming the company already quietly install updates, and the backdoor is not secured worse than the auto-update mechanism, this does not really give them additional capabilities. (Also, the phone likely already has more serious vulnerabilities.)
Of course, this exchange does suggest bad things about the company's ethics and competence.
The backdoor being called "backdoor" by this engineer already implies that it is not nearly as secure as the auto-update mechanism: the content is not signed by the company, it can't be disabled by the user, et c. I see no reason not to trust OP's judgement.
Comments
Devil's advocate: assuming the company already quietly install updates, and the backdoor is not secured worse than the auto-update mechanism, this does not really give them additional capabilities. (Also, the phone likely already has more serious vulnerabilities.)
Of course, this exchange does suggest bad things about the company's ethics and competence.
The backdoor being called "backdoor" by this engineer already implies that it is not nearly as secure as the auto-update mechanism: the content is not signed by the company, it can't be disabled by the user, et c. I see no reason not to trust OP's judgement.