Precisely, I truly do not understand how these people witness a potentially catastrophic event of such proportions and instead of asking "dear God, I wonder how many backdoors there are in the Windows operating system that we don't know and will never find out about!?! Thankfully Linux and its ecosystem can be somewhat audited!". Instead they go full blown "please make it go away, if it's visible by us it means it's terrible and dangerous! FOSS is insecure!"
I've said it once[1] and I'll say it again: FOSS delivered both on its pitfalls and its strengths.
Moreover, and I'll never get tired of repeating this:
Although this might be indeed a FOSS-exclusive or FOSS-adjacent kind of risk that ultimately materialized, as some would like to call it, it’s nevertheless also an issue where checks and balances that are only intrinsically possible in FOSS worked as expected and needed. Yes, there was an element of luck in the discovery of CVE-20240-3094, but it is undeniable source code availability and other FOSS customs tipped the scale in the community’s favor.
[1] https://jdsalaro.com/note/xz-liblzma-linux-backdoor-foss-pit...