To use a hardware wallet safely now, you need to use a disposable email, a pseudonym, a burner phone, find a neutral but secure shipping location, and pay in anonymized bitcoin. None of that screams "ease of use" to me, especially not for a newbie. If newbies are going to spend the time to follow all the steps in this thread to buy a hardware wallet, they would be better off just learning how to set up a proper airgapped cold storage wallet instead.
Add something else to your list. When you connect your Trezor to "their" website, which most newbies will do, the connection URL captures YOUR exact device ID# every single time! Do they use it/record it? Of course they will say no, but we will never be able to know for sure. This means numerous wallets/mpk's all reflect back to the exact same device ID#. Not exactly anonymous is it, should Sat Labs ever go nefarious?
Still I use several Trezors and have learned to safeguard myself, but I am miles from being a newbie. The business side of their house has sent me running from anything Ledger. I received numerous bogus emails from them, but fortunately all went to tutamail and no further. Those accounts are closed now.
With the unpatchable critical vulnerability in Trezor devices
What, which?? My SD card removes any I am aware of. Fake SD is perfect for when I store my Trezor too.