|
|
|
|
|
by 9wzYQbTYsAIc
1840 days ago
|
|
Apparently there’s criminals that only trust other criminals (also apparently, those same criminals are highly likely to betray each other) and those trusted criminals are saying “use this phone, it’s secure”. Plus, managing DIY security is more complicated than just running Signal on an encrypted phone. Same concerns regarding supply chain interdiction, remote code execution, and other security vulnerabilities on the operating system running Signal. |
|
Yes, but specifically to supply chain security, as this attack shows, the most affordable option to secure your supply chain is to ensure your devices and downloads cannot be uniquely targeted.
Buying a stock iPhone in cash and downloading Signal from the App Store is a far better approach than buying a "drug dealer phone."
I do think this attack, as you imply, simply highlights how hard it is for even motivated consumers in the market to make actually secure choices, which in turn is why the market underemphasizes real security improvements.