HN 提问:您会信任移动键盘层面的加密吗?

3 分•作者: dkatsura•3 个月前
大多数私信建议都说:使用安全的通讯工具。 这对于传输和服务器端隐私来说是合理的,但每条手机消息在到达通讯工具之前都会存在于某个地方。在 Android 上,这个地方通常是键盘/输入层。 问题: * 你是否会信任键盘进行与加密相关的操作? * 在你认为安全之前,这样的键盘需要证明什么? * 输入层的隐私是有用的,还是会造成过多的信任障碍? * 仅本地/无网络是否足够,还是需要开源/审计? 无产品链接。我试图理解威胁模型和用户体验方面的顾虑。
查看原文
Most private messaging advice says: use a secure messenger.<p>That makes sense for transport and server-side privacy, but every mobile message exists somewhere before it reaches the messenger. On Android that place is often the keyboard&#x2F;input layer.<p>Questions:<p>- Would you ever trust a keyboard for encryption-related workflows? - What would such a keyboard need to prove before you considered it safe? - Is privacy at the input layer useful, or does it create too much trust friction? - Is local-only&#x2F;no-network enough, or would you need open source&#x2F;audit?<p>No product link. I am trying to understand the threat model and UX objections.