Incidentally, no I have no objections against closed source. I find the religious dogma behind FOSS patently stupid.
I mean, no, I would dispute you, because everything Microsoft is doing in those products isn't publicly available for the world to see.
Still probably pretty unlikely because those products are hugely popular and widely scrutinized.
As I said, I think it's still pretty unlikely that Microsoft products are compromised by a state actor. It's certainly not part of my threat model. I'm not sure what point you're trying to make though. I certainly wouldn't install a system-wide HTTP proxy from a developer I didn't trust. And I don't have much of a choice but to trust Microsoft, their products are so ubiquitous I often have little choice.
Of course, you do have a problem as you've already made clear. However, that problem stems from how Microsoft's code is closed source compared to Google's open source code. That's religious FOSS dogma which I referred to earlier, and has nothing to do with whether programmers are paid to write and examine your code.