They claim it’s “zero knowledge” proof through Google pay, meaning that Google will know you paid Signal, and Signal knows you paid them, but there is no link between the two that uses your PII payment info to identify the Signal account.
I’m inclined to believe them.
That’s not ok either! Just stop playing these games and stop obstructing self hosting. When they come to round up all the Signal users, they won’t care what account belongs to who. So there should be no database that identifies the users.
Unless you wait a good while to use what you paid for (if that’s even possible), then I doubt it’d be hard to connect the dots. Never mind connecting transaction records.
Not quite. With a phone number a random phone provider knows your identity. They do not get notified you are signing up for Signals. Google doesn’t know you signed up with that phone number for Signals either. Depending on your country and how these details are handled there may not be an easy way to lookup who you are from a phone number.
There’s obvious downsides to the phone number use, of course, but saying it the same in terms of privacy than this, doesn’t feel correct.
There’s identical security for the payment too. Assuming you trust Signal, they don’t keep a record of it tied to your actual account the same with a phone number.
They claim it’s “zero knowledge” proof through Google pay, meaning that Google will know you paid Signal, and Signal knows you paid them, but there is no link between the two that uses your PII payment info to identify the Signal account. I’m inclined to believe them.
If they pass through Google infrastructure, then it’s a no.
Also, why would you have to pay for something that should be a completely free and basic feature?
They’re completely off the rails.
Bot protection
If Google and Signal collude can they link payments to accounts via timing attacks? My guess is yes
That’s not ok either! Just stop playing these games and stop obstructing self hosting. When they come to round up all the Signal users, they won’t care what account belongs to who. So there should be no database that identifies the users.
If “they” get to the point of rounding up all Signal users, not using Signal will not prevent you from being rounded up.
Unless you wait a good while to use what you paid for (if that’s even possible), then I doubt it’d be hard to connect the dots. Never mind connecting transaction records.
It’s the exact same privacy protection as signing up with a phone number.
Not quite. With a phone number a random phone provider knows your identity. They do not get notified you are signing up for Signals. Google doesn’t know you signed up with that phone number for Signals either. Depending on your country and how these details are handled there may not be an easy way to lookup who you are from a phone number.
There’s obvious downsides to the phone number use, of course, but saying it the same in terms of privacy than this, doesn’t feel correct.
There’s identical security for the payment too. Assuming you trust Signal, they don’t keep a record of it tied to your actual account the same with a phone number.
Oh, also, they’re just using Google Play for now. They’ll definitely be adding a generic CC option.
“Your Signal code is…”
Could use a refillable credit card.