Earlier quoted context omitted.
Attacker needs physical access to just one device in the whole product line that uses the same encryption key. After that, all you need is to get the device to update using the bitstream you made. In some cases this could be remote attack.
I'm not sure this is true. This attack allows reading the encrypted bitstream, but it doesn't say anything about allowing you to sign modified bitstreams.
This seems to be saying that it's possible