I doubt any FOSS restriction is doable at all. As for the supply chain - xz showed this is indeed possible… But no one can guarantee that every encrypted client would be able to get such a well-hidden backdoor, and that it will stay undiscovered, and that it wouldn’t be invalidated with an update… But yeah, the only way this can be combatted is having more eyes on such software.
I doubt any FOSS restriction is doable at all. As for the supply chain - xz showed this is indeed possible… But no one can guarantee that every encrypted client would be able to get such a well-hidden backdoor, and that it will stay undiscovered, and that it wouldn’t be invalidated with an update… But yeah, the only way this can be combatted is having more eyes on such software.