Earlier quoted context omitted.
I wonder if those supposedly secure Linux distros are actually secure. Anything from MS, Google, and Apple cannot be trusted.
Well unless you are building everything from source (after auditing software), you end up trusting someone for the executable (packaged by distro maintainers). Distros like Gentoo solve this pretty well by giving a good suite of build tools, Nevertheless it's too bothersome for most users. Arch distributes it's package signing abilities to multiple maintainers who can revoke each other's keys. which imo is better tha…
Unless the code is coming from the University of Minnesota. :)