Everyone knows that their firmware releases are closed-source.
No, everyone doesn't. We do, but most of their customers probably have no clue.
The open-source claims are misleading, but they refer to Ledger's app development porta - the native and 3rd-party crypto apps. Those are open-source.
Yes, I know. But it is intentionally misleading, and they know it. They're printing intentionally misleading information on their boxes to trick people into thinking the device in the box runs on code that is open source, or worse, trick people into thinking the device in the box and the code for that device is 100% open source, none of which is true.
Ledger prints "WE ARE OPEN SOURCE" on the box of a closed source device that runs closed source code. That's fraud. It's like printing "WE MAKE HEALTH FOOD" on a box of poison because the company that makes the poison also makes health food.
Ledger is dirty. They can't be trusted.