So, if there is a bad firmware (for whatever reason), how can i be sure that the exported firmware from nitrokey storage is the one on the key, ie, who/what control the export of the memory ?

and the same goes on reflashing, could a firmware be done in such a way that it would accept to be reflashed, but without reflashing (ie, just reflash a copy, but still use a bad one for day to day operation) ?

Fill in the blank.