(Replying to PARENT post)
If the NSA is in bed with US based network gear providers
If ^^that^^ is true, then I'd argue your first sentence is not. There is simply no way to truly protect yourself if the gear manufacturers are complicit.
๐คrufugee๐11y๐ผ0๐จ๏ธ0
(Replying to PARENT post)
This is infeasible for a lot of organizations, unfortunately. And it also becomes much more difficult if your adversary has full control of your DNS servers or can perform a man-in-the-middle due to their backbone Internet access. Something like an Evilgrade (https://github.com/infobyte/evilgrade) attack conducted via an ISP MitM is very hard to detect and prevent, and I suspect NSA uses Evilgrade-like tactics frequently. And if you live in the US it's game over by default, since they can legally send people onsite to compromise you.