It would be better if Tails did not include any non-free software.
Unfortunately they are targeting people who may be using PCs not under the
users control (people who may be using a computer at and internet cafe for
instance). That use case makes it difficult to exclude non-free
driver/firmware software as near everybody here knows or should know most
computers are not free software friendly.
That said your absolutely right. The non-free software included in Tails is a
security risk. Fortunately for those who are not utilizing PCs dependent on
non-free software it shouldn't load.
Tails has cleaned itself up a bit over the years. For example Tails added
TrueCrypt, but later decided to remove it over licensing and closed
development issues if my recollection serves me right. While all the code to
TrueCrypt is/was available during its lifetime it didn't or at least may not
have met free software licensing standards. It used a non-standard license
which the intent of was not clear-but in it said something to the effect for
'academic purposes'.
We know that one of the original developers who wrote code that eventually
turned into TrueCrypt was pro release of source and considered any encryption
software that did not reveal the source to be something you could not trust.
Most people won't recall this as it pre-dates TrueCrypts existence/popularity
under the name TrueCrypt. What most people also don't know is TrueCrypt is
derived from the source code of two different applications. It's popular
believef it comes from E4M, but there is another application called
Scramdisk. It was the later which I can confirm was pro-release of source.
SecurStar eventually bought the merged software, but there was already source
released under the quasi-free license. I firmly believe SecurStar's claims
over total ownership to be fraudulent in some respect as the code was already
licensed such that it could be modified and redistributed by others. I do
believe they bought the copyright to the code however. I always thought the
company never really understood what it had bought. The developers who sold
the code may have mislead or not revealed the licensing. However it seems
they should have done there research. The developers did shut down the site
and it was not for a year or more later that TrueCrypt came about. The only
thing I'm not sure about is the GNU/Linux code base. This was never released
from my recollection as it was unfinished at the time the code was sold. I
don't know if the developers licensed it without publishing it and therefore
considered it OK to use or if it was re-written or what. None of this is
public information.