问HN:你会信任移动键盘层的加密吗?

3作者: dkatsura大约 1 个月前原帖
大多数私人消息传递的建议是:使用安全的消息应用。这对于传输和服务器端隐私是有道理的,但每条移动消息在到达消息应用之前,都会在某个地方存在。在安卓系统中,这个地方通常是键盘/输入层。 问题: - 你会信任一个用于加密相关工作流的键盘吗? - 这样的键盘需要证明什么才能让你认为它是安全的? - 输入层的隐私是否有用,还是会造成过多的信任摩擦? - 仅限本地/无网络的安全性是否足够,还是你需要开源/审计? 没有产品链接。我试图理解威胁模型和用户体验的反对意见。
查看原文
Most private messaging advice says: use a secure messenger.<p>That makes sense for transport and server-side privacy, but every mobile message exists somewhere before it reaches the messenger. On Android that place is often the keyboard&#x2F;input layer.<p>Questions:<p>- Would you ever trust a keyboard for encryption-related workflows? - What would such a keyboard need to prove before you considered it safe? - Is privacy at the input layer useful, or does it create too much trust friction? - Is local-only&#x2F;no-network enough, or would you need open source&#x2F;audit?<p>No product link. I am trying to understand the threat model and UX objections.