It most surely can be patched. Allow a USB device to offer up a signature that the PC can verify. The CA would be the manufacturer which has a private key for each USB key manufactured (so hackers can't steal one private key and copy it). Make sure the manufacturer revokes keys that are compromised. Bam, instant manufacturer guarantee that the hardware is genuine. That is, until the private key is uncovered by the hackers, but that's what expiration dates are for I suppose.