Wasn't that feature "optional" though? I believe the user needs to turn the feature on before Recovery could be enabled?
But if I'm misinformed, and that Ledger actually does get the user's seed phrase from the device, then that obviously opens a wide attack vector.
Of course, this option is presented as
optional because otherwise it makes no sense. The thing is that there is no way to determine whether the seed can be extracted from devices that do not have this option enabled.
Putting that from a Game-Theory viewpoint, I personally believe that they would not do it because that would mean a non-zero chance of lawsuits, and reputational damage of their business.
In addition, there should be no doubt that hackers are very interested in hacking that system because it would theoretically enable them to extract the seed from the user's device remotely.
Yeah, no one can debate against the possible attack vectors. There's ALWAYS a non-zero chance that it would be exploited.
I am a former user of their devices. At one point I concluded that for the best security I can only trust air-gapped setups, and for everything else there are other hardware wallets with a much better reputation.
Trezor One is still the best if you ask me. Everything is Open Source.