The source code alone is less problem than the private keys.<p>If the agencies have private keys of the creators of your OS, who then signed the "signed updates" you've got?<p>Example, recently from Microsoft:<p>In their forums: "Is Update KB3103709 Fake?"<p><a href="http://answers.microsoft.com/en-us/protect/forum/protect_other-protect_start/is-update-kb3103709-fake/c9fea314-1469-4d6f-b22f-d1fa0c11c503?auth=1" rel="nofollow">http://answers.microsoft.com/en-us/protect/forum/protect_oth...</a><p>On their site: " Try searching for what you need This page doesn’t exist."<p><a href="https://support.microsoft.com/en-gb/kb/3103709" rel="nofollow">https://support.microsoft.com/en-gb/kb/3103709</a>