(Rant)
At somepoint, HSBC decided KDE Connect installed via F-Droid is less secure.
Then it decide non-whitelisted keyborads are a security risk. Only Gboard and Samsung Keyboard is confirmed within the whitelist.
I understand the point that risk can be introduce at various points, yet this is simply too much. Yeah there are people phone infected by malware but from Play Store. Not a single time I heard one ever happened on F-Droid distributed apps, at least not from the official repo. Also, I will put more trust on an open source keyboard than any proprietary keyboard.
Furthermore, I’m shocked that an app can read my app list, and current keyboard (introduced in Android 14). This just make building a profile much easier as I belive everyone almost have an unique set of apps they like. I don’t think any apps need such functionality. Why the f it needs to care what input devices I uses? This make me worry more about untold (aka burried deep in Privacy Policy) data collection.
We seriously need a way to sandbox apps, where they cant see shit outside their sandbox
https://f-droid.org/packages/com.oasisfeng.island.fdroid/
Afaik that’s how the corporate apps stuff works, I byod (I really should have a second phone) and the work stuff is totally on its own, uses a different keyboard, opens a different browser uses a different authenticator etc.
If only we had that
Also a way to spoof the input.