HN 提问:您会信任移动键盘层面的加密吗?
3 分•作者: dkatsura•3 个月前
大多数私信建议都说:使用安全的通讯工具。
这对于传输和服务器端隐私来说是合理的,但每条手机消息在到达通讯工具之前都会存在于某个地方。在 Android 上,这个地方通常是键盘/输入层。
问题:
* 你是否会信任键盘进行与加密相关的操作?
* 在你认为安全之前,这样的键盘需要证明什么?
* 输入层的隐私是有用的,还是会造成过多的信任障碍?
* 仅本地/无网络是否足够,还是需要开源/审计?
无产品链接。我试图理解威胁模型和用户体验方面的顾虑。
查看原文
Most private messaging advice says: use a secure messenger.<p>That makes sense for transport and server-side privacy, but every mobile message exists somewhere before it reaches the messenger. On Android that place is often the keyboard/input layer.<p>Questions:<p>- Would you ever trust a keyboard for encryption-related workflows?
- What would such a keyboard need to prove before you considered it safe?
- Is privacy at the input layer useful, or does it create too much trust friction?
- Is local-only/no-network enough, or would you need open source/audit?<p>No product link. I am trying to understand the threat model and UX objections.