This is an important perspective people need to consider when talking about security issues of an app.

Signal does not defend against a fully compromised phone, neither is it responsible for Spyware on your device that extracts messages you send or sniffs your keystrokes. https://twitter.com/pwnallthethings/status/1358861679019384833
Signal is also not responsible for the keyboard you chose as your default.

Signal provides the option to turn on Android’s incognito keyboard flag. IME’s can choose to ignore it. Again, this is an Android feature, not something Signal can enforce.

https://support.signal.org/hc/en-us/articles/360055276112-Incognito-Keyboard
You might be wondering, why does Signal not set this flag by default? The same reason why WhatsApp doesn’t.

It disables autocorrect and stops fixing your typos. Most people want autocorrect for convenience. Those that don’t want it for specific reasons can explicitly disable it.
You can follow @Fox0x01.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.