问HN:你会信任移动键盘层的加密吗?
大多数私人消息传递的建议是:使用安全的消息应用。这对于传输和服务器端隐私是有道理的,但每条移动消息在到达消息应用之前,都会在某个地方存在。在安卓系统中,这个地方通常是键盘/输入层。
问题:
- 你会信任一个用于加密相关工作流的键盘吗?
- 这样的键盘需要证明什么才能让你认为它是安全的?
- 输入层的隐私是否有用,还是会造成过多的信任摩擦?
- 仅限本地/无网络的安全性是否足够,还是你需要开源/审计?
没有产品链接。我试图理解威胁模型和用户体验的反对意见。
查看原文
Most private messaging advice says: use a secure messenger.<p>That makes sense for transport and server-side privacy, but every mobile message exists somewhere before it reaches the messenger. On Android that place is often the keyboard/input layer.<p>Questions:<p>- Would you ever trust a keyboard for encryption-related workflows?
- What would such a keyboard need to prove before you considered it safe?
- Is privacy at the input layer useful, or does it create too much trust friction?
- Is local-only/no-network enough, or would you need open source/audit?<p>No product link. I am trying to understand the threat model and UX objections.