I think you're misunderstanding what I'm trying to argue. There's important context to what we're talking about: Linux.
The argument is not: "Having source code makes it trustworthy"
The increase in trust is primarily driven by unaffiliated experts. The open source part makes that easier, but is not what explicitly drives the trust.
***The multi-party verification is what drives trust.***
> practically speaking normal users have just as much "control" over their stuff whether it's running Linux or Mac or Windows in the end.
No one is arguing against this. I even agree with you.
I brought up the difference in trust by third party due to this. The level of trust is different. While /control/ may be the same /trust/ is not.
It does not matter that FOSS is written by people that are paid. It matters that people that are not paid look at it and investigate it. Or even paid by a different party. Paid or unpaid is not the critical variable here.
Look at it this way:
In a closed source ecosystem, do you trust an organization that has had a 3rd party audit MORE THAN one that hasn't?
Of course you do! It isn't complete trust, and certainly you may wish to (and should) scrutinize the third party auditors to ensure that they aren't just acting as "yes men", but the level of trust objectively increases. Certainly this should continue to increase as the number of parties grows. That's because the likelihood that these parties are "on the dime" decreases.
> Do you trust the pills made by a pharmaceutical company to actually be what it says on the box more than a guy handing out pills at a concert?
This is significantly different from the scenario we're discussing... Let's rephrase
Which pills would you trust more to do what they claim to do?:
1) Pills made by a pharmaceutical company and tested by the pharmaceutical company
2) Pills made by a pharmaceutical company and tested by the pharmaceutical company, tested by third party organizations (medical and governmental) from multiple countries and have received recommendations from various organizations with no direct ties to the pharmaceutical company that developed the pills
Clearly we trust #2 more.
You'd be insane not to! It'd require a much more complex environment for that to be lest trustworthy with such high amounts of conspiracy that you may as well trust nothing that you can't verify yourself. But in that setting you can't trust your own knowledge because you aren't able to derive everything from scratch either. You literally can't trust the knowledge that you read in a book, on the internet, or anywhere if there is that level of conspiracy. But clearly we don't believe in that ludicrous scenario.
Certainly there are a lot of shit FOSS out there that is no better than the drug dealer in your example, but we're talking about fucking Linux, not a random GitHub project by some uni student. Certainly I don't trust that one! But that one doesn't have multi-party vetting and is far from the type of software we're talking about.
I hope we're on the same page now.