People don't trust Mozilla because they read the code, they trust Mozilla because they do exactly what was described above. They do the things that foster trust.
I'm afraid Firefox is so abysmal noone could comprehend the whole project's code. Guess, we could only review a tiny bits of it (I had briefly read sync-related parts of code in hope I could replace them with something saner and simpler, but ditched the idea) and hope others did the same for other parts.