5,848 karma · joined December 5, 2012
Big scary warning, I like it. Swiftkey does badger people to enable it though, so presumably it's sending a lot of data back to their servers as a business model. Nasty.
I'm not sure I can quite get used to this particular theme at all. The colors are pretty gaudy, the main action buttons (brown and purple) particularly are almost unreadable to me. I couldn't find the input boxes at all even though they had a header, they just parse as horizontal rules rather than something I can click on an add text. I respect the effort that has gone into creating this, but on a fundamental level I don't feel this is a good step in interface design.
It's not even if I have one installed, the people I communicate with will be using them too, and they can compromise me.
Do you have a privacy policy somewhere with details about the information you collect from the application? I was unable to find any on your website.
[0]: http://www.reddit.com/r/Bitcoin/comments/23sjle/chrome_exten....
[1]: http://www.reddit.com/r/Bitcoin/comments/1vrium/a_google_chr...
I don't think signed addresses will be particularly effective. With the sort of key stores we have now, it seems pretty plausible that a bad actor to get a certificate that would pass on the Trezor device. It raises the barrier of entry a little though.
[0]: The rebuttal for this will be signing every request with details of it with a hardware dongle, but would you want to do this for every action in your email client? If the answer is "no", you're owned. Ultimate security is unusable, and doesn't really solve anything outside of the most astute of professional users. Just writing this post I would need 4 signatures, one to log in, one to post, one to fix a typo, and yet another to add this footnote. Would I be able to handle that? No way, I'm far too lazy for that.
[1]: The issue is that perfect compromise is impossible to detect. I can be reasonably confident on a heavily sandboxed device like an iPhone that there's little in the way of malware that would affect me. The downside being that I have no tools or methods of analysis if I thought it was compromised. There's no such confidence on the computers I use on a daily basis. I've always thought we have confirmation bias with malicious software. We only notice the dumb stuff while the smart goes unnoticed.