or if the user don't buy from official store/reseller and don't bother check HW wallet's genuinity
I believe the only correct/safe purchase of hardware wallet can be directly from the manufacturer, for me personally resellers are not option.Even the manufacturers itself states they are a reliable source of purchase. The possibility of manipulation on the way from the factory to dealers is only an extra risk that is not worth it.
I'm surprised there's a sale though honestly, trezor and ledger are the main devices that are good for this (the ledger blue's seemed cool but I couldn't decide whether to get one or just use an old phone to store keys - $220 is quite steep). Although there are a few alts I'd like to use but don't because I don't quite trust the source (it's not from the original developer or it's blocked by AV).
Why do you ever think about Ledger Blue? Except the touch screen by its functionality/security it does not differ from the Ledger Nano S, and a few weeks ago you could buy 4 Ledger Nano S (50% discount from 100$) for the price of one Ledger Blue - with this 30% discount you can still buy 3 Nano S for the price of one Blue.
Old phone for storage of private keys? It is possible of course, but I do not consider it in any way safer way then HW, only cheaper. If you still decide on something like this here's a first-hand experience.
Using old phone for cold storage