So it appears that the central servers were compromised by the police, and then they delivered a poisoned "security" update to the devices. It's not clear if "security" updates were mandatory or not, but whatever the case most of the users ended up with the update installed. Because why not, right? Who doesn't want a security update? And the real question to ask before updating is whose security is being updated?

They should have been using a P2P setup, or tor, or something; not a centralised system.

In the words of Douglas Adams:
"Yeah, well, just for safety, OK?" said Zaphod.
"Whose? Yours or mine?"

