OP presents SEs as green/good and lack thereof as red/bad. I agree that there is certain situations where a SE can save the day but equally does the SE with their NDA-requirement and secrecy lead to a situation where we trust a black box a whole lot for being our own bank and throw "don't trust - verify" too easily over board.
I was neutral in this case, and I simply showed a color, green generally means GO, red color means STOP in traffic, but there is nothing good or bad about that.
I can also say that tomato is red and cucumber is green, but that doesn't mean either of them are good or bad.
If you read what I wrote, I actually said that secure elements can potentially be exploited by malicious firmware updates, and I wrote many times about dangers of hidden NDAs.
Especially hardware wallets that use their SE's TRNG as sole source of entropy should be called out! Nobody can prove the TRNG to be truly random and in the worst case it just creates hash("you won't guess this", serialNumber, sequenceNumber) "random" numbers that the inventor can trivially guess. Such a hardware wallet would allow the provider to know all the private keys generated by all the users, putting him in the position of being able to pull the rug at any time.
I already wrote a topic about Seed Generation in Hardware Wallets including entropy, and I am somehow aware of flaws with random generation (TRNG, HRNG, PRNG) but I am not at all expert and I don't understand deeply how they actually work.
You are free to contribute this or any other of my topics and correct any potential mistakes I made:
https://bitcointalksearch.org/topic/seed-generation-in-hardware-wallets-5317199As you can see in my footer, I work on WalletScrutiny where my primary goal is to prevent rug pulls as I see them as a systemic risk if we get another MtGox situation where half the community is affected. Reliance on a compromised TRNG is one of my big concerns.
I know your work, but I doubt MtGox can be repeated with hardware wallets.
More likely scenario is that some government agency or malicious actor infiltrate any spy from the inside.