Related question… How can an app developer guarantee end to end encryption when the main entry point is almost always a virtual keyboard? Seems like the weakest part of the chain.
Yeah, fair point and largely the point of the article. Too many conditions exist for Signal to accidentally reveal information. I still wonder how many people assume the privacy offered is much more than just the data in transit. I’d bet a large percentage of users believe that.
No one can guarantee any thing. Not even most gods or a time traveler from 1000 years in the future. An omnipotent being could.
It makes sense to attack and work on problems that are actually happening and are solvable within some level of aspiration.
I’m not sure how things work on either mobile OS. Perhaps there can be more clear language and notifications on if everything is being passed to the virtual keyboard developer or not.
Unless you mean Apple, Google, and other Android manufacturers themselves. That’s beyond the scope of any E2E stuff.