How do you guys know these trezors and ledgers aren't getting intercepted in the mail and their guts stuffed with something else?
I believe that the latest TREZOR devices are shipped empty (without f/w). You then go to SatoshiLabs's site and download it yourself. When you install it, a special "fingerprint" (a long alphanumeric string) appears on the computer's screen, which you must compare with the one that appears on TREZOR's screen. If they match, the f/w is not tampered with.