Thanks, James. I think you're hitting the nail squarely on the head here.... You've given me much to think about!
The truth of the matter is vastly different.
Can you name anyone who as actually done a security audit on every single binary and source file they use?
In other words, the assurances people seek by paying for software are fictitious from the start. The very same is true for open source software.