What prevents the firmware replaying a transaction with a valid signature? You're relying on the device to give you a true copy of the firmware it's running, but that means trusting something that's not trustworthy.
One could use some sort of RSA secure token technology that would be very hard to replicate the state of at the time of the attack. I guess my point is that there's loads of ways USB could be used in a secure fashion. To say it can't be "patched" is completely unfounded in reality.