They claim it’s “zero knowledge” proof through Google pay, meaning that Google will know you paid Signal, and Signal knows you paid them, but there is no link between the two that uses your PII payment info to identify the Signal account.
I’m inclined to believe them.
That’s not ok either! Just stop playing these games and stop obstructing self hosting. When they come to round up all the Signal users, they won’t care what account belongs to who. So there should be no database that identifies the users.
Unless you wait a good while to use what you paid for (if that’s even possible), then I doubt it’d be hard to connect the dots. Never mind connecting transaction records.
Not quite. With a phone number a random phone provider knows your identity. They do not get notified you are signing up for Signals. Google doesn’t know you signed up with that phone number for Signals either. Depending on your country and how these details are handled there may not be an easy way to lookup who you are from a phone number.
There’s obvious downsides to the phone number use, of course, but saying it the same in terms of privacy than this, doesn’t feel correct.
There’s identical security for the payment too. Assuming you trust Signal, they don’t keep a record of it tied to your actual account the same with a phone number.
I’ll call it right now and bet they want 3DS supported cards. So no giftcards and no prepaid cards.
I use signal all the time but even I will admit some of the things they do don’t scream privacy conscious to me. This is one of those things.
For instance, no support for their shitty crypto no one ever uses? You know, the one they chose over an actual battle tested one like Monero? (Its basically a pump and dump, look at the all time chart on coingecko for Mobilecoin went from like $50 a coin to 0.07¢ now)
Nope. Just traceable cards or traceable phone numbers. Interesting choice. The lack of self hosting is also an interesting choice.
Way better than Telegram or Facebook or WhatsApp for sure for sure and I get all my friends to use signal but I do have doubts sometimes when I start to notice stuff like this.
People will get on here and say “only FEDS promote fud about signal!!” But honestly ask yourself if what you just read really aligns with privacy in any way. A lot of it does not.
Even the same people who hate crypto actively use signal which did its own pump and dump scheme. Its odd. And I wish an actual competitor would come out that isn’t based in another surveillance state like the UK.
Literally all the alternatives are from surveillance States. Every single one. All of them.
And if it does support gift cards and prepaid cards?
This seems to me like a mild annoyance for someone using it legitimately, but a bigger barrier for scammers trying to get accounts in bulk. Sure they can get a lot of accounts still, but it’ll no doubt be lessened.
If they were going to do that they would not have just made an announcement about google pay’s “zero knowledge proofs” being the only way to pay it.
It becomes more than a mild annoyance it becomes borderline suspicious to be quite honest. None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.
Idk man. The phone number thing I could kind of understand but now the only way around it is a google pay payment? What the fuck is that? The fact that they won’t even accept their “super private” shitcoin is a huge red flag here to be completely honest. Just gonna call a spade a spade. Its a very strange choice from a privacy oriented service.
Its like using the Tor browser or something but you have to do a “zero knowledge proof” payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?
Can I buy an account on a device that has no Play Services?
Not yet. We have plans to add more payment methods, but currently only offer Play Store in-app payments, which requires Play Services.
I do not think this is suspicious. They are starting where most of their users are, and whether we like it or not, is play services.
Their implementation with play services seems to be correct if it were done for privacy, though we can’t ignore the fact it’s still supporting Google.
The fact that they won’t even accept their “super private” shitcoin is a huge red flag here to be completely honest.
Nobody uses this. Signal also never processes a card. You have to transfer money from another crypto. That is not user friendly, and people would be pissed about this implementation too.
None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.
The open source decentralized projects? Those a great, and important, but they are different. Signal is balancing security with convenience. Most average people would give up the moment it asked for an instance. Signal is easy to use, even for the tech illiterate. It works just like their other messaging apps, but only because it’s centralized.
Its like using the Tor browser or something but you have to do a “zero knowledge proof” payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?
It’s about where the users are. Most tor users are going to be on a desktop device, probably Linux, maybe Windows, then everything else. A very small percentage are going to be on Android. It would be very weird to be on a Linux device in a Tor browser being sent to Google services for payment. Signal is a mobile messaging app, which means basically two ecosystems. I assume they started with play services because of number of users and/or the fact Google already had ZKP payment as an option.
And ZKP isn’t new, and it is real, and it’s exactly how more things should be implemented.
Look at how many scammers use WhatsApp, and how much spam there is. Signal is clearly trying to make it tje best user experience they can without compromising security. This is just one step further, and it’s only the first payment method, not the last.
But why not also accept crypto, like Bitcoin? That way actual privacy conscious people can just convert monero to bitcoin for a trustworthy decentralized private payment
The way I see it, that’s next. This feature is in beta, and I imagine they wanted to rollout the payment method that would be most used, or maybe easiest to implement first for testing. They have already officially said more payment methods will come, but they have not said what those payment methods will be. Given they already have their own crypto, that will almost definitely be one of the options
“That’s next” given that it took them years to make phone # optional, I’m not optimistic that this will happen anytime soon. Not to mention their current payment method requires play services, which has probably already de-anonymized the user
I have never trusted them, I always considered many of Signal’s decisions highly questionable, and I think they are either pressured into them by the US government, cooperating in what they think are limited and carefully-implemented ways while claiming and perhaps even believing they are fighting the good fight, or maybe they are just a psyop honeypot to begin with. I cannot trust them, and if they truly wanted me to, they would not do so many things that require me to trust them.
Yeah… Combine all that with being based in the US under the fascistic Trump admin, and I’m considering trying to get my friends and family to swap to a self-hosted XMPP server or something, but there are a couple elderly relatives that might complicate that.
Very few online services accept. I’ll eat my hat if I’m wrong and hell I’ll sign up with one if they take them, but I sincerely doubt they will accept these.
You mean they want to identify you from your credit card instead of your phone number? Bah.
They claim it’s “zero knowledge” proof through Google pay, meaning that Google will know you paid Signal, and Signal knows you paid them, but there is no link between the two that uses your PII payment info to identify the Signal account. I’m inclined to believe them.
If they pass through Google infrastructure, then it’s a no.
Also, why would you have to pay for something that should be a completely free and basic feature?
They’re completely off the rails.
Bot protection
If Google and Signal collude can they link payments to accounts via timing attacks? My guess is yes
That’s not ok either! Just stop playing these games and stop obstructing self hosting. When they come to round up all the Signal users, they won’t care what account belongs to who. So there should be no database that identifies the users.
If “they” get to the point of rounding up all Signal users, not using Signal will not prevent you from being rounded up.
Unless you wait a good while to use what you paid for (if that’s even possible), then I doubt it’d be hard to connect the dots. Never mind connecting transaction records.
It’s the exact same privacy protection as signing up with a phone number.
Not quite. With a phone number a random phone provider knows your identity. They do not get notified you are signing up for Signals. Google doesn’t know you signed up with that phone number for Signals either. Depending on your country and how these details are handled there may not be an easy way to lookup who you are from a phone number.
There’s obvious downsides to the phone number use, of course, but saying it the same in terms of privacy than this, doesn’t feel correct.
There’s identical security for the payment too. Assuming you trust Signal, they don’t keep a record of it tied to your actual account the same with a phone number.
Oh, also, they’re just using Google Play for now. They’ll definitely be adding a generic CC option.
“Your Signal code is…”
Could use a refillable credit card.
Could possibly use a gift card?
I’ll call it right now and bet they want 3DS supported cards. So no giftcards and no prepaid cards.
I use signal all the time but even I will admit some of the things they do don’t scream privacy conscious to me. This is one of those things.
For instance, no support for their shitty crypto no one ever uses? You know, the one they chose over an actual battle tested one like Monero? (Its basically a pump and dump, look at the all time chart on coingecko for Mobilecoin went from like $50 a coin to 0.07¢ now)
Nope. Just traceable cards or traceable phone numbers. Interesting choice. The lack of self hosting is also an interesting choice.
Way better than Telegram or Facebook or WhatsApp for sure for sure and I get all my friends to use signal but I do have doubts sometimes when I start to notice stuff like this.
People will get on here and say “only FEDS promote fud about signal!!” But honestly ask yourself if what you just read really aligns with privacy in any way. A lot of it does not.
Even the same people who hate crypto actively use signal which did its own pump and dump scheme. Its odd. And I wish an actual competitor would come out that isn’t based in another surveillance state like the UK.
Literally all the alternatives are from surveillance States. Every single one. All of them.
Idk man, I have doubts a lot.
I miss Wikr before it enshittified
Smh, now I have to get a Nintendo credit card?
(if you don’t get it, read the above comment again)
And if it does support gift cards and prepaid cards?
This seems to me like a mild annoyance for someone using it legitimately, but a bigger barrier for scammers trying to get accounts in bulk. Sure they can get a lot of accounts still, but it’ll no doubt be lessened.
If they were going to do that they would not have just made an announcement about google pay’s “zero knowledge proofs” being the only way to pay it.
It becomes more than a mild annoyance it becomes borderline suspicious to be quite honest. None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.
Idk man. The phone number thing I could kind of understand but now the only way around it is a google pay payment? What the fuck is that? The fact that they won’t even accept their “super private” shitcoin is a huge red flag here to be completely honest. Just gonna call a spade a spade. Its a very strange choice from a privacy oriented service.
Its like using the Tor browser or something but you have to do a “zero knowledge proof” payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?
It’s weird.
Their original post says this:
I do not think this is suspicious. They are starting where most of their users are, and whether we like it or not, is play services.
Their implementation with play services seems to be correct if it were done for privacy, though we can’t ignore the fact it’s still supporting Google.
Nobody uses this. Signal also never processes a card. You have to transfer money from another crypto. That is not user friendly, and people would be pissed about this implementation too.
The open source decentralized projects? Those a great, and important, but they are different. Signal is balancing security with convenience. Most average people would give up the moment it asked for an instance. Signal is easy to use, even for the tech illiterate. It works just like their other messaging apps, but only because it’s centralized.
It’s about where the users are. Most tor users are going to be on a desktop device, probably Linux, maybe Windows, then everything else. A very small percentage are going to be on Android. It would be very weird to be on a Linux device in a Tor browser being sent to Google services for payment. Signal is a mobile messaging app, which means basically two ecosystems. I assume they started with play services because of number of users and/or the fact Google already had ZKP payment as an option.
And ZKP isn’t new, and it is real, and it’s exactly how more things should be implemented.
Look at how many scammers use WhatsApp, and how much spam there is. Signal is clearly trying to make it tje best user experience they can without compromising security. This is just one step further, and it’s only the first payment method, not the last.
But why not also accept crypto, like Bitcoin? That way actual privacy conscious people can just convert monero to bitcoin for a trustworthy decentralized private payment
The way I see it, that’s next. This feature is in beta, and I imagine they wanted to rollout the payment method that would be most used, or maybe easiest to implement first for testing. They have already officially said more payment methods will come, but they have not said what those payment methods will be. Given they already have their own crypto, that will almost definitely be one of the options
“That’s next” given that it took them years to make phone # optional, I’m not optimistic that this will happen anytime soon. Not to mention their current payment method requires play services, which has probably already de-anonymized the user
I have never trusted them, I always considered many of Signal’s decisions highly questionable, and I think they are either pressured into them by the US government, cooperating in what they think are limited and carefully-implemented ways while claiming and perhaps even believing they are fighting the good fight, or maybe they are just a psyop honeypot to begin with. I cannot trust them, and if they truly wanted me to, they would not do so many things that require me to trust them.
Yeah… Combine all that with being based in the US under the fascistic Trump admin, and I’m considering trying to get my friends and family to swap to a self-hosted XMPP server or something, but there are a couple elderly relatives that might complicate that.
Very few online services accept. I’ll eat my hat if I’m wrong and hell I’ll sign up with one if they take them, but I sincerely doubt they will accept these.
IDK maybe that’s possible but I’d rather avoid Signal, except maybe for a self hosted fork.
Not me. But the author.