This may be a useful notion and term to start using when thinking about these things: https://en.wikipedia.org/wiki/Threat_model (not being smirky; I should use apply it more often myself, e.g.)
With this in mind, I'll link my prev comment: https://news.ycombinator.com/item?id=43095936
> Israel’s supply chain attack on Hezbollah’s pager source
You know, James Mickens, a CS researcher at Microsoft had a very related article (PDF), "This world of ours": https://www.usenix.org/system/files/1401_08-12_mickens.pdf
See Figure 1. He calls it the "Mossad / Not-Mossad threat model" :) (but, joking aside, it's good to identify oneself on a scale, or expectations for some system scale-wise and property-wise (incl. which security properties, esp. privacy vs. anonymity!) before looking closer at it.