Indeed. That is what I wrote:
"When something changes the functioning of the hardware and users don't know
about it", well, there is nothing that can be done against it: we all depend
on mass-produced software and, even if documentation is provided, malware
would not be described in it.
By only accepting free software, we can know of the driver/firmware running
on our machines. If malware is implemented in the hardware (or in
non-flashable ROM), there is, today, no remedy. We are back to what rms says.