My guess for this is that they're checking for a new signature, or if the MD5 equals something known.
The new signature probably isn't loaded from the cert anymore, either, they learned their lesson on that one.
If you can patch after install, though, it'd be rather trivial to put a new OS in there. Do the standard unlock tricks still work?