Ask HN: Would you trust encryption at the mobile keyboard layer?

https://news.ycombinator.com/item?id=48797491
by dkatsura • 18 days ago
3 2 18 days ago

Most private messaging advice says: use a secure messenger.

That makes sense for transport and server-side privacy, but every mobile message exists somewhere before it reaches the messenger. On Android that place is often the keyboard/input layer.

Questions:

- Would you ever trust a keyboard for encryption-related workflows? - What would such a keyboard need to prove before you considered it safe? - Is privacy at the input layer useful, or does it create too much trust friction? - Is local-only/no-network enough, or would you need open source/audit?

No product link. I am trying to understand the threat model and UX objections.

Related Stories

Loading related stories...

Source preview

news.ycombinator.com