Mostly yes except last bit.
There is no possible way for Ledger/ government to edit the firmware of the Ledger hardware device to make it export your Private Keys (assuming it can’t do that already, we don’t know because not FOSS)
It could be a genius move on behalf of Ledger cos people don’t...