Not sure where that one is, but there is a wealth of data here: http://www.nsa.gov/ia/mitigation_guidance/index.shtml
It's safe to assume they left a few things out, but part of NSA's mission is to protect the communications of US interests (government and enterprise) so it actually is part of their mandate to give advice like this.
First: peer review. If your design documents are readily available, researchers don't have to reverse engineer them. Also, by open sourcing hardware design you lower the bar for critique: you might get feedback from an experienced electrical engineer who might not know how to write and upload a custom firmware for a USB controller.
Second: you can easily change it because it's not a black box.