Open source really is irrelevant. We don't know what code they deployed - it could be an open source project (we hope so), it might be an open source project with some minor changes - an NSA-approved backdoor for example, etc. We don't have any guarantee, so far as I'm aware, of what they're running, much less that it does what it claims to do.