Without bootstrapping and reproducibility, you are trusting -one- person to build and sign for everyone else, and hoping their device was not compromised at build time. Single point of failure.
Without deterministic full source bootstrapped builds, you cannot verify a build someone else did was not tampered with at build time.
I did not say every user reproduces. In practice 2+ _maintainers_ reproduce and sign on behalf of all users, avoiding trust in any single computer or machine.
This is my point. Bootstrapping and reproducibility are made up problems that people think are important but are not actually needed.