Earlier quoted context omitted.
> I'm not aware of any case law around whether private keys are copyrightable That's often up to debate, apparently. I think most recently, Widevine private keys regularly get DMCA'd.
Distributing the keys is illegal, but what about using they keys and distributing the resulting signed firmware?
Depending on how you look at it using another's entity's cryptographic key to sign something that then "pretends" to have been produced by that entity might classify as forgery.
Though this is just my personal thoughts, not sure if that would hold up in practice. Technically you own the hardware, so "forging" the signature yourself for your hardware probably wouldn't be an issue, but distributing it might be.