Note: I'm Paul the designer
You're completely right someone could put some other firmware on the image but have it return the correct one - we solve this by:
- padding the image to the size of the ROM (256k, the runtime image is ~10k)with random data making it incompressible
- signing the image (including the random bit) so that the image can't be altered
On a linux system the udev install script kicks off a process that starts with verification of the firmware image and finishes with putting it into service if verification passes.
This is open hardware - you can program it yourself, we'll be releasing both the hardware design and all the software in a little while - along with programmer for doing it - you just wont be able to create an image signed by us - but you can sign images and share them with your friends.
Note: what you can't do is program the device over the USB
As far as lifting the lid and verifying what's underneath is concerned we don't expect every user to open it and look at the board and understand how it works (we hope some people will and will verify our work) - but what you can do is look under there and verify that the board looks the same as images that we publish.