Comment Re:There is a simple solution... (Score 2) 102
Except that that's exactly what they've done [ncsc.gov.uk], and been doing for the last ~decade. I don't think there's ever been a company that's had their work so thoroughly scrutinised by the security services.
Opening up the source code isn't nearly enough, you have to trust the trust the whole process of building and deploying the software. How do you make sure that the binary wasn't tampered with between compilation and the factory floor? How do you know that the compiler itself didn't inject a backdoor?