This is a bunch of nonsense, assumption and leaping to conclusions without evidence. "In the second screenshot, we have the public key that’s authorized to access the device. The email address attached to the public key, eng@eightsleep.com, to me suggests the private key is likely accessible to the entire engineering team." He has no evidence for this whatsoever and not really any good reason to assume it either. "In…
I'm not sure what kind of evidence or reason you're looking for, I think their assumption is pretty sensible.
> This isn't how SSH works
Maybe I'm just naive, but the wording of it to me seems nontechnical enough that I think the author is skipping over things on purpose. For example, how exactly that "far way" host he thinks is involved.
I'd personally imagine it's a reverse shell type deal going on, although why SSH needed to be involved in that I'm not sure. Could be just a hacky implementation. But it's really not that far removed from sensibility, vendors popping reverse shells without authorization really wouldn't be new.
> It is clearly intended to draw traffic to their company website, which is some kind of venture-backed security startup.
Didn't even notice that. Can't imagine too many other people did either. So maybe not so clearly?