Yeah, these things quickly boil down to the trusting trust thing (see Ken Thompson's Turing award lecture). You can't trust any system until you've designed every bit from scratch.
You gotta put your trust somewhere, or you won't be able to implement jack.
Maybe use a RAM based fs? Some distros mount
/tmp
as tmpfs into the RAM. You can look into that.