When Geopolitics Breaks the Security Model of Consumer Technology

Technology restrictions intended to reduce strategic security risk can also create new security problems for ordinary users when they fragment app stores, identity systems, updates and trusted software-distribution channels.

Original article date: 1 January 2024

Article type: Commentary

A consumer problem created by a geopolitical dispute

My interest in this subject began with something mundane: a problem with a Huawei GT3 watch.

What should have been a straightforward consumer-technology issue exposed a much larger problem. Restrictions affecting the relationship between Chinese technology companies and US platform providers have changed how some devices integrate with familiar software ecosystems.

The result can be a fragmented user experience involving alternative app stores, side-loading, additional accounts and unfamiliar software-distribution channels.

That raises an uncomfortable question:

Can a policy intended to reduce security risk at a geopolitical level create additional security risk at the consumer level?

Security depends on an ecosystem, not just a device

Consumers often evaluate security by looking at the hardware product: the phone, watch or application.

In practice, security also depends on the surrounding ecosystem:

When geopolitical restrictions split those ecosystems, users may be pushed toward less familiar processes.

Fragmentation creates complexity

A fragmented technology environment can require users to manage:

Complexity is itself a security concern.

Every additional step creates another opportunity for user error, impersonation, stale software or misunderstanding.

Side-loading changes the trust decision

Mainstream app stores are not perfect, and malicious applications have appeared in them. But they provide a familiar distribution model with some centralised review, signing, update and takedown mechanisms.

When users are asked to side-load software or obtain applications through less familiar channels, the trust decision moves closer to the individual consumer.

The user now has to answer questions such as:

Most consumers are not equipped to perform that analysis every time they install an application.

The issue is not "Chinese technology is insecure"

It is important not to turn this discussion into a simplistic national-security stereotype.

A product's country of origin does not by itself determine whether it is secure, and geopolitical restrictions may be driven by strategic, economic, legal and national-security considerations that extend far beyond an individual consumer device.

My concern is narrower: what security model is left for the user after the restriction is imposed?

If the answer is "download software through an unfamiliar route and trust that it is legitimate," then the policy has created a new operational risk that should be acknowledged.

Security policy should account for second-order effects

A strong security decision considers not only the risk being removed, but the behaviour the control creates.

For example:

Control: restrict access to a dominant app ecosystem.

Intended effect: reduce strategic dependency or exposure.

Possible side effect: users obtain software through alternative channels.

New risk: weaker assurance, fragmented updates, increased side-loading and user confusion.

This does not automatically mean the original restriction is wrong. It means the second-order effects should be part of the security analysis.

What good consumer security would look like

Whatever the geopolitical environment, consumers need:

These controls should remain available even when technology ecosystems diverge politically.

Choice and interoperability matter

Interoperability is not only a convenience issue.

When devices can use established identity, update and security mechanisms, consumers benefit from familiarity and consistency. When those mechanisms are fragmented, switching costs and security complexity increase.

The long-term risk is a world of technology silos in which users must understand several incompatible trust models simply to operate ordinary consumer devices.

Conclusion

The US-China technology conflict is usually discussed in terms of national security, economic competition and strategic independence.

For consumers, however, the effects are much more immediate: which app can I install, where do I obtain it, which account do I trust, and how do I know it is safe?

Security policy should therefore be judged not only by the threat it intends to remove, but also by the security behaviour it creates.

If a control pushes ordinary users toward more complex and less transparent software-distribution practices, that consequence deserves to be measured as part of the risk decision.