Earlier quoted context omitted.
Shouldn't Signal then also warn or refuse to work on Android versions with known vulnerabilities? Or if there are apps installed on the device with the accessibility permission? Where would you say the line should be drawn?
I feel like this is somewhat disingenuous. IME keylogging is a known, serious, and frequently exploited issue that affects a substantial portion of Signal users. Signal's "Incognito Keyboard" setting didn't mention that the flag can be ignored, which was misleading and dangerous. But yes, warning about accessibility settings if there's evidence of that being an attack vector seems like a good idea. I don't know about…
Do you happen to have a source for this? There’s lots of speculation out there, but I’ve never seen anyone claiming to have proof of this being frequently exploited.