I don’t have ultimate trust in any software or hardware, but I get to “good enough” by deciding which providers I trust: * Software: Canonical, Google, Microsoft, Valve, Oracle, Dropbox. I install software from their official repos and keep it up to date. Anything 3rd-party/unofficial/experimental/GitHub goes in a VM. * Hardware: I built my main PC from mainstream commodity components. I have no way of knowing if the…
What about publicly known backdoors in your hardware? https://www.techrepublic.com/article/is-the-intel-management... There is hardware that doesn't contain those at least, but it doesn't break power records.
(This is not an argument for mass surveillance, it's just a practical assessment of the risk).