os-issue-tracker
os-issue-tracker copied to clipboard
Implement “Scramble Keyboard Input Layout” as a Lock Screen Option for Passphrase Users
GrapheneOS currently provides an option to enable "Scramble PIN Input Layout" to mitigate class of attacks like fingerprint smudge guesses, shoulder surfing, and public surveillance. The downside is that this option only applies if you use a PIN, not a passphrase which is much more secure.
But the added security of using a passphrase is moot if you are affected by the aforementioned class of attacks and in those cases, it would have been more secure to use a PIN to take advantage of the scrambling feature.
A setting should be implemented to enable "Scramble Keyboard Input Layout" to protect users who use passphrases.
These class of attacks affect both PIN and passphrase users and the scrambling feature should be available for everyone to enhance security and privacy.
That would be useful but not many would enable it, the time needed to input a long password with a scrambled keyboard is too much.
Another thing that I'm sure many would benefit for is removing the pressed key popup while entering the password.
@thestinger what is the aosp keyboard name? I think it's a keyboard related issue