Do you think it will resolve the issue without losing the keys?
I use the key to encrypt some important information and really hoping to be able to decrypt it.
If there is even a small risk of data loss, I would rather export the key first, decrypt the data and then update the firmware.
In case you created the GPG key to device, you cannot restore a public key from the data that gets exposed by the Nitro key. Unfortunately, the public key gets derived onetime during creation based on the asymmetric secret material that never leaves the token. So a full backup includes the saved public key that gets created together with the private key. Without that, you can still use the GPG key for ssh but not for receiving GPG encrypted messages.
Reading something like that on a forum run by a company that makes its living selling security products is, of course, complete nonsense!
If I can’t rely on such products, why do I need them AT ALL, as long as there are software solutions that have been working for decades?
It’s also less about providing guarantees that no one will ever be able to compromise a product, since that would likely be nearly impossible.
However, the fact that a product functions in such a way that it can never lose the user’s data should not only be the standard, but must also finally be enshrined in law!