And there's enough people with such a key to choose from: https://www.archlinux.org/master-keys/.
(I run Arch as well, but I have no such illusions of security.)
Edit: not to discredit Linux of FLOSS, at least there is the possibility to analyse the source code.
Where there's a will there's a way especially if you have billions of dollars in funding and the freedom to do so i just aim to make it as difficult as possible.
There's a lot of things you can do to protect you privacy but it all starts with a good choice of OS and hardware.
If the foundation is compromised there's no point in anything else you do to protect your privacy.
Edit: Yes Arch it's not particularly security conscious I choose to compromise some security to stay on the bleeding edge now that could mean that I get some bad code sometimes but that also means that it gets fixed sooner too.
Having a rolling release system that you can mold to your needs is worth it for me.
So it runs on i686 and amd64 only. How do you select "good" hardware?
However since there's no such thing you will have to choose who you trust.