> *** Going a step further, you could have a wireless keyboard that you
> flash with your firmware,

... if have access to the necessary information or can reverse-engineer

>           ____________________
> _   _____/                    \_   _____.---------.
>  | |                            | |                \_____
>  | | USB  Secure Hardware Key   | | USB to Keyboard _____
> _| |_____                      _| |_____,----------|
> ^.       \____________________/         `----------'

Nice :-)

> The USB Secure Hardware Key

I.e., something like the critters made by: Ugoos, Rikomagic,
Tronsmart, FXI (Cotton Candy), Inverse Path (USB Armory), etc.

> would offer 3 functionalities:
> 1. bootable Tails system
> 2. wireless keyboard connection
> 3. cabled keyboard connection
> Both 2. and 3. would provide the encryption capability.

If the wireless keyboard encrypts, you'd also have it in case 1.
And yes, that's an entirely feasible scenario. Differences to the
simple USB-to-USB encryptor I described:

- considerably more complex and harder to make (but you can try to
  use a pre-built system, see above),

- more expensive,

- does not protect input going to the PC if the "sandbox system"
  is compromised. But yes, Tails is probably a good deal more
  secure than the pandemonium the average person keeps on their PC.

The Keyboard -> USB computer -> PC -> Internet -> Secure remote case
is a bit weaker than the keyboard -> USB-to-USB-encryptor -> PC ->
Internet -> Secure remote case irrespective of the condition of the
PC because the USB computer has a much larger attack surface.

> And if you remove the wireless part, and use micro-USB instead, you can
> have a fully featured encrypted keyboard for your mobile phone, which is
> probably a good thing to have given that we have more fingers than two
> thumbs.

May get a bit fumbly, though: smartphone + USB stick + keyboard.

