This is a very tough cookie to crumble. The counter-argument to "we are open source" is that the binaries can potentially be assembled from an altered source code. Ideally, the binaries should be assembled by multiple independent "build points" and compared against vendor's version. There was a secure smartphone OS vendor (the name escapes me ATM, it was several years ago) and they did just that - an open source project with audited build system - and it was a major hassle by the looks of it.
The only sure way to deal with the trust issue is to not have a conflict of interest to the first place, which is something that seems to be neigh impossible with Chrome.
This is a very tough cookie to crumble. The counter-argument to "we are open source" is that the binaries can potentially be assembled from an altered source code. Ideally, the binaries should be assembled by multiple independent "build points" and compared against vendor's version. There was a secure smartphone OS vendor (the name escapes me ATM, it was several years ago) and they did just that - an open source project with audited build system - and it was a major hassle by the looks of it.
The only sure way to deal with the trust issue is to not have a conflict of interest to the first place, which is something that seems to be neigh impossible with Chrome.