It's very hard to think someone would get to the trouble of creating and using a secure chat application, but then fail to secure its distribution.
It's very hard to think someone would get to the trouble of creating and using a secure chat application, but then fail to secure its distribution.
I've tested many applications which claim to be secure, designed for security/privacy sensitive tasks, yet are very easy to compromise (simple OWASP top 10 stuff).
Even if the app developers are great and know their stuff, I can still see them slipping up on the distribution. It's normally handled for most developers and is outside the realm of any secure development guidelines they might be following.
If both you and I have an shared app, then we have some shared data and protocols we can use to protect our communications and maintain security, but when you download an app you do not yet have any protection unless that protection is provided by an app store (and such app store protections disappear at the first court order).
Bootstrapping security over insecure channels against nation state threats is close to impossible, maintaining security you have already achieved over a brief window of time is still hard but achieve given existing technologies. I see no evidence ISIS is capable of doing either. As further evidence observe that the US just blew up their super secret cash reserve.