I dont trust anyone working with debian or google.
but debian I can be sure if someone saw a bug/malware happening or in the source, I'd benefit from that. with closed systems the source option is gone. also nobody can report a ISP MitM the binary packages because no one knows the actual build output.
so, trust noone, but acept that open source gives you an edge. always.