> I think the biggest implication is how far they're willing to go to compromise commerical hardware.
This.
Phone basebands, the Intel ME[1], NICs, Windows, anything from Cisco; they all have to be considered broken.[1] With Linux, at least there is a public code history, but considering the value of the target, tricky code can't be ruled out, nor can attacks at the distribution/packaging layer.
Vernor Vinge wrote a fun book called _Deepness in the Sky_, which, among other things, explores some implications of untrustworthy computing.
[1] And plenty of things not on that list, and perhaps something on it isn't. But for some risk models, they have to be assumed broken.