So, it sounds as if you somehow get keyboard that has been tampered with, a firmware update that is bogus, or someone has physical access to your keyboard and hacks it, you are in deep doo-doo.
So, someone could go into a workplace with a laptop, unplug a keyboard, plug it into their laptop and modify it, then plug it back in with nobody the wiser.
Crap.
Wouldn’t it be just as easy for the user to flash his firmware with the correct version and thus, make sure everything is “okay”?
It also seems like it would not be a problem for software to be made which would read the firmware, compare it to the current version of the firmware and note if there was any differences.