I didn't look into this deeply, but my understanding is that it's opt-in. Do we know that people using Ledger are being put at significant additional risk just by upgrading their firmware, if they don't opt into any backup stuff?
Ledger compromised again.
https://twitter.com/Ledger/status/1735291427100455293