for everyone waxing poetic about the xz backdoor: please, please, _please_ remember that risk acceptance is as important to threat modeling as risk reduction / abatement
you’re not going to come up with a single, all-encompassing piece of security advice that works for everyone — security always is a balancing act between capability, risk, and potential outcomes
sometimes you legitimately have to accept that these kinds of things are possible and move on*