About time. We need open and verifiable firmware, at the very least, to be able to trust anything. Now if only they'd turn this lens on American-made devices which are likewise opaque, insecure, and likely to be weaponized against us as soon as security updates stop....
How? Even ignoring ASICs, I just don't see how it's possible. Even if you had no binary blobs anywhere (we are already in the wonderland), with process for turning source to binary, you need to trust compiler, cpu, flashing hardware and software and the whole lot of other things.
And that's all ignoring the fact that hiding bad stuff in open source is many orders of magnitude cheaper than finding it.
I don't think we have even a theoretical plan for fixing computer security, it just becomes ML bots arena.