Peter Todd says Ledger’s authenticity scheme leaves a key security gap, because it cannot verify whether the user interface was altered in a man-in-the-middle attack. He argues tamper-evident shipping is essential and says recent events validate that warning.