> A Chinese manufacturer (possibly many manufacturers) builds a wide variety of Android-based devices, including phones, tablets, and CTV boxes. At some point between the manufacturing of these products and their delivery to resellers, physical retail stores and e-commerce warehouses, a firmware backdoor— based on Triada malware—gets installed and the product boxes are sealed in plastic, priming these devices for fraud on arrival at their destination.
Isn't it OK to name that manufacturer and affected brands?
US brands deal all the time with dilution due to counterfeits made in sketchy factories.
Why protect the manufacturer/brands in this one case? Especially when there's a particularly problematic supply chain problem involving the manufacturer, and to which they might be especially vulnerable (if not complicit or even the perpetrator)?
In addition to the obvious reason of providing negative feedback to parties involved and in a position to improve, the last sentence of the article demonstrates how not naming them hurts legitimate but lesser-known/upstart brands who are not involved and who don't deserve the negative feedback:
> recommending that users choose familiar brands when purchasing new products.