None of these were exploited to retrieve this data, and the third party app that was installed was not intended to encrypt conversations given that it was a honeypot.
> popular apps
This was a small app unknown by anyone outside of criminal orgs. It had no "legitimate" non-criminal users.
> especially in the US
The app was deployed in Australia.
> can always be commandeered
Why distribute a random app when they could have gotten the criminals to use Signal or Telegram and bust them there?
> as long as you're not actively targeted
How long did it take to find Bin Laden?
> despite using "secure" apps
This was not a secure app and any audit would have revealed this (audits such as the ones that Signal and friends have undergone).
> and stuff like Tor,
Tor was not involved.
> media makes it seem are unbreakable.
None of the apps hyped as "unbreakable" were broken here, so...point still stands, I guess?
Honestly, if anything, the recommended approach from this incident would be to use the walled garden - an FBI-backed honeypot would have a lot harder time getting from the App/Play Store onto a user's phone if it was obviously a scam to collect user conversations, asked for a bunch of permissions, had no reviews, and no apparent update history. Who would download some random chat app that nobody uses?