Well, many Trezor customers and prospective customers do not seem to be aware of that risk yet. And I am not sure that the SatoshiLabs people are aware of the risk that they incur by tacitly approving the re-selling of their Trezors.
seriously? If they forebode reselling im sure craigslist would still have some.
the trezor is well-built. A knockoff requires some serious dedication and isnt even a remote concern if you just buy directly from buytrezor.com
far more likely:
1) printers with custom firmware to recognise bitcoin addresses/QR codes when printing, and push that data to a server
2) casascius or any other coins being opened up with precision and solvents, private key copied, then sealed shut again for resales. Or even the creator keeping a copy of all private keys
3) an android/windows/ios/ANY wallet software that was downloaded from the wrong site or updated to a malicious version
4) a webwallet that is hacked or otherwise steals privkey data.
5) virus or malware that seeks and steals any wallet info, or even QR codes from your print/documents history, and pulls the funds out.
someone creating an exact replica of the trezor and its (quality) box that its shipped in, plus valid serial numbers, plus making it match the MD5 hash..... you are pulling at straws. IMO the trezor is 100% the safest option right now outside of operating an isolated offline system with an offline printer, using it to sign txs, copying the signed tx to a USB, then sending the signed transactions from an online system