this is something i hadn't taken seriously enough. it's not wrong.
if backdoors get deep enough in the supply chain it can be hard to be sure you ever got rid of them.
we should, for example, be spending special effort on securing all systems related to building compilers