Not necessarily true, you can do it with just a display (and two buttons) like the Trezor does[1]. You can probably even omit the buttons using this model:
1. Send message to sign over the wire
2. Display message to sign on the device's screen
3. Send a message to continue or reject over the wire
4. Device displays scrambled pinpad
5. User enters PIN on the compromised computer, using a blinded pinpad (like the Trezor)
6. The blinded PIN is sent over the wire to the device
7. The device verifies the PIN, and if correct, signs the message displayed in step 2
8. The signed message is sent over the wire to the compromised device
[1] https://doc.satoshilabs.com/trezor-user/enteringyourpin.html