

They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.
Which is clever, to be fair. Whether or not that’s legal is already a court case. The law is so frightfully grey.




The premise seems to suggest that the target companies’ security measures remain locked in at current levels. So while the attacker models scheme and plan and infiltrate, they do not notice or they do nothing. I don’t think that would be realistic.
I also don’t think the targeted companies don’t already feed all their data into some models. There will be beaches and poorly configured LLMs - the prize won’t be as juicy, the impact of the grand conspiracy won’t be as big.
I think the sky will not fall here.