So my choice is to trust one of either: 1. The Mozilla developers who are capturing telemetry, but probably just using it to push ads (at worst, and possibly not even that). 2. Some new devs who may have good intentions, but who are unknown to me, who are not capturing telemetry, but nevertheless have control over my browser.
It's just a custom build of the latest Firefox version with some patches applied. Everything is very well documented and you can build it by yourself, there is no need to trust "some new devs who may have good intentions"
One of the key pieces of open source is the larger a project, the more people will be incentivized to monitor the code for malicious changes. This distributes the burden to a much much larger pool therefore minimizing the burden to single nodes across the board.
Is it perfect? No, absolutely not. Do malicious or unintentional bugs slip through? Sure. But when it comes to scaled out projects, nothing is perfect and never will be. I certainly trust a large open project with years of reputation built up and a large user base significantly more than a large closed source project or large and open with no reputation.
There are of course valid criticisms of this model but I’ve yet to see an alternative put forward that isn’t fraught with its own issues.
I do find it strange how over the past few years we’ve seen a number of people who engage in a whiplash type behavior where they see minor problems with a model so they whiplash away into a far worse model with far more serious problems.