We can complain and yell at Ledger in our ivory tower of knowledge and understanding of hardware wallets. We aren't the target users for Ledger, Paris with their opaque "you have to trust us" firmware. It's been said before, Ledger has good marketing and established a mantra that their obscurity model is something good, at least to an audience and user base who is too lazy to learn or understand the basics.
Ledger provoced a shitstorm and does now the sole thing they do well, a lot of bullshit marketing and throwing fog candles to blind the masses. Their eulogy and "dedication" for open-source is a joke and double slap in the face. Their timeline is pure bullshit and fog-in-the-air to delude and calm down opposers.
If someone still thinks the user has everything under control with the buttons on your Ledger NoNo, well good luck with your illusion. You might now have the control, but that must not be the case in the future when Ledger Live nags you to perform a firmware update or nothing will work until you obey.
The opaque firmware controls the MCU and secure element, the MCU controls the display and the buttons AND communicates with the secure element. The hardware buttons aren't wired directly in any way to the secure element where most important magic happens. The secure element runs firmware under control of Ledger and does only what the MCU tells the secure element to execute. The firmware is a black box and Ledger can program whatever they like. That is mostly the reality of Ledger f***ing NoNos. And if Ledger users would put a few brain cells together they could've know this even before the Recovery service debacle. Oh, wait, "You have to trust us"-Ledger lied all the time... too bad.
inb4 the introduction of Ledger Autopilot™ -- Keep your hardware wallet automatically updated without any hassle for just $19.99,- a month!*
*subscription fee withdrawn automatically for your convenience
Don't give 'em ideas. Or paid Ledger Live & firmware updates. Or new Ledger NoNo Rec(t) for a symbolic single figure price but with mandatory Recovery service paid monthly
* (I reuse your starred legend, hehe)