If you think the #xz backdoor exposes the fragility of open source, consider how much easier it would be for a state actor to do the same in a proprietary component.