I am not sure people realize how centralized is the development of Knots. There is very little if any code review and a single person with write privileges to the repository.
I guess he can sneak a malicious code any moment without people noticing. He or somebody else if his account gets compromised. And his accounts were compromised in the past, when his Bitcoins were stolen.
I hope the above poll is not representative and 30% of the network will not run Knots just for this reason alone. Nothing against Luke and I am no taking sides in the OP_RETURN debate.
Yeah, I haven't personally. Might be beyond my expertise but I have heard this from multiple sources (devs). I think it's generally understood to be so, it's just that some say that the configurations are "opinionated".
I did some comparison of the source code of both and posted in this thread. Note that a single line of buggy code is enough to end up with a remote backdoor, intentional or not.
diff
and evaluate the differences.