Top
Best
New

Posted by Cider9986 6 hours ago

Registration without a phone number on Signal will use zero-knowledge proofs(community.signalusers.org)
119 points | 63 comments
ggm 3 hours ago|
For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.
Cider9986 2 hours ago||
Here's an article saying that: https://aboutsignal.com/news/signal-allows-android-phones-to...
opengrass 3 hours ago||
You can already do that without being a trusted device.
ggm 2 hours ago||
For the longest time, you couldn't. It wasn't until this release I realised that had changed. If it changed before, it wasn't well communicated to me as an Android signal user. I was on beeper and then molly precisely because there was so little traction on changing this. You could install signal fine, but you couldn't QR code or secret phrase mesh it with your android handset. Oddly, iPad meshed fine with iPhone or Android, and OSX desktop likewise. Just Android tablet which didn't.

Do you think this changed in over 18 months? I think it changed in under 18 months.

sysguest 5 minutes ago||
any link to presentations/papers on this?

I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much

purpleidea 3 hours ago||
Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
s0ss 3 hours ago||
I’m not sure their tax status is the justification your argument needs.
what 31 minutes ago||
OpenAI is 501c3, should they also be required to release everything?
gbriel 10 minutes ago|||
Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.
alightsoul 24 minutes ago|||
Yes
opengrass 3 hours ago||
Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
Cider9986 3 hours ago||
It says something about Play Billing being used specifically to mitigate spam?

I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.

opengrass 2 hours ago|||
Add ability to pay for a signal login.

https://github.com/signalapp/Signal-Android/commit/7da3357b5...

Cider9986 2 hours ago||
Ah, I thought you meant using google play to do the payments to prevent spam unrelated to the cost. I know they are costing something.
wolvoleo 2 hours ago|||
Ugh wtf so I need a Google account on Android? That's not going to happen.

For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.

Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

HWR_14 29 minutes ago|||
Are you being hyperbolic, or do you really consider Google the worst with regards to privacy.
wolvoleo 14 minutes ago||
The most ubiquitous, absolutely. Their data collection is unparalleled. They're on almost every website, app, they have fingers into payment and browsers and mobile OSes.

In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.

Cider9986 2 hours ago||||
Hopefully they eventually make a way to pay without it.
genrader 2 hours ago||
You wouldn't believe the spam if they did that
Cider9986 2 hours ago||
Why? Just raise the prices if they get more spam on non-google payments.

I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.

thin_carapace 2 hours ago|||
googles obligation to hand out all account linked info notwithstanding, one may still create google accounts without associating a phone number, by doing so on old android versions. signal does however explicitly force credit card info here, thus providing direct individual traceability ..
wolvoleo 1 hour ago||
Plus they are mandating you give your details to Google. So much for privacy
mmooss 3 hours ago||
What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.
wolvoleo 1 hour ago|||
True, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.
Cider9986 3 hours ago||||
Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.

They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.

wolvoleo 2 hours ago|||
I always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.
dakolli 1 hour ago|||
They avoid Monero because Signal and the EFF are actually the feds and this is all theater.
Cider9986 52 minutes ago||
Claims without evidence can be dismissed without evidence.

Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.

If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?

They are the largest messenger that has E2EE backups by default.

Jhater 26 minutes ago||
[dead]
drum55 2 hours ago|||
I've literally never seen anybody mention it, much less use it since it was announced.
ynniv 3 hours ago||
you can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful
teravor 2 hours ago|
usually, the implication of ZKP is that you buy coupons and claim them without attribution. in this coupon scenario the ZKP can just be a blind signature scheme.

however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.

rkagerer 3 hours ago||
Lots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?
Cider9986 2 hours ago|
Likely soon.
Cider9986 2 hours ago||
I'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.
smalltorch 2 hours ago||
The commit history is kinda wild
2Gkashmiri 1 hour ago||
I know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems.

https://timesofindia.indiatimes.com/india/ats-probes-use-of-...

https://www.aninews.in/news/national/general-news/accused-da...

https://www.deccanherald.com/india/secure-messaging-apps-lik...

https://india-employmentnews.com/tech-category/delhi-blast-n...

https://timesofindia.indiatimes.com/tech-news/Dangerous-Sign...

And it doesn't matter you use a connected phone or not, they just get data from ISPs.

And yes, using a VPN will get you knocked up as well.

https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-k...

wolvoleo 1 hour ago||
Yes that's bad but that's an Indian government problem, not a signal or other messenger app problem. And really, it sounds like there was a lot more going on with these people than just using a particular app. Discord and WhatsApp are mentioned too.

India also bans most satellite phones by the way. I have one so I looked into that as to not get caught out travelling.

Cider9986 48 minutes ago|||
And WhatsApp is E2EE with the same protocol so I don't see the big deal.
2Gkashmiri 35 minutes ago||
The big deal is, having talked to security people, they are "fine" with WhatsApp because the theory is, they get data from whatsapp so they have some sort of backdoor access. They are pretty chill with WhatsApp which id unexplainable
Synthetic7346 1 hour ago|||
What if I use a VPN as a dude? Still gonna get knocked up?
wolvoleo 1 hour ago||
You will be if you drop the soap after you get arrested :)
s5300 18 minutes ago||
[dead]
victorbvieira 2 hours ago|
[flagged]
More comments...