Every major vendor has vulnerabilities introduced all the time, by accident! No talent is necessary to introduce a bugdoor, just malice.
You can already verify that a toolchain wasn't backdoored today, reproducible builds aren't necessary for that.
You can already verify that a toolchain wasn't backdoored today, reproducible builds aren't necessary for that.
How, exactly?
If we both compiled hello.c (a prototypical hello world program), and exchanged binaries; how would you verify my build wasn't malicious?
That does require reproducible builds, but here is how to do it without reproducible builds:
Take the trusted source code, then compile it to make a trusted binary. Now put the untrusted binary in the trash, cause you already have a trusted binary :)