And if it does support gift cards and prepaid cards?
This seems to me like a mild annoyance for someone using it legitimately, but a bigger barrier for scammers trying to get accounts in bulk. Sure they can get a lot of accounts still, but it’ll no doubt be lessened.
If they were going to do that they would not have just made an announcement about google pay’s “zero knowledge proofs” being the only way to pay it.
It becomes more than a mild annoyance it becomes borderline suspicious to be quite honest. None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.
Idk man. The phone number thing I could kind of understand but now the only way around it is a google pay payment? What the fuck is that? The fact that they won’t even accept their “super private” shitcoin is a huge red flag here to be completely honest. Just gonna call a spade a spade. Its a very strange choice from a privacy oriented service.
Its like using the Tor browser or something but you have to do a “zero knowledge proof” payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?
Can I buy an account on a device that has no Play Services?
Not yet. We have plans to add more payment methods, but currently only offer Play Store in-app payments, which requires Play Services.
I do not think this is suspicious. They are starting where most of their users are, and whether we like it or not, is play services.
Their implementation with play services seems to be correct if it were done for privacy, though we can’t ignore the fact it’s still supporting Google.
The fact that they won’t even accept their “super private” shitcoin is a huge red flag here to be completely honest.
Nobody uses this. Signal also never processes a card. You have to transfer money from another crypto. That is not user friendly, and people would be pissed about this implementation too.
None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.
The open source decentralized projects? Those a great, and important, but they are different. Signal is balancing security with convenience. Most average people would give up the moment it asked for an instance. Signal is easy to use, even for the tech illiterate. It works just like their other messaging apps, but only because it’s centralized.
Its like using the Tor browser or something but you have to do a “zero knowledge proof” payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?
It’s about where the users are. Most tor users are going to be on a desktop device, probably Linux, maybe Windows, then everything else. A very small percentage are going to be on Android. It would be very weird to be on a Linux device in a Tor browser being sent to Google services for payment. Signal is a mobile messaging app, which means basically two ecosystems. I assume they started with play services because of number of users and/or the fact Google already had ZKP payment as an option.
And ZKP isn’t new, and it is real, and it’s exactly how more things should be implemented.
Look at how many scammers use WhatsApp, and how much spam there is. Signal is clearly trying to make it tje best user experience they can without compromising security. This is just one step further, and it’s only the first payment method, not the last.
But why not also accept crypto, like Bitcoin? That way actual privacy conscious people can just convert monero to bitcoin for a trustworthy decentralized private payment
The way I see it, that’s next. This feature is in beta, and I imagine they wanted to rollout the payment method that would be most used, or maybe easiest to implement first for testing. They have already officially said more payment methods will come, but they have not said what those payment methods will be. Given they already have their own crypto, that will almost definitely be one of the options
“That’s next” given that it took them years to make phone # optional, I’m not optimistic that this will happen anytime soon. Not to mention their current payment method requires play services, which has probably already de-anonymized the user
It tooks years to implement the whole functionality. They also weren’t working on this feature the whole time, but it was on the list. Adding another payment method isn’t the same.
Not to mention their current payment method requires play services, which has probably already de-anonymized the user
I agree it’s not great to require play services, but it isn’t going to always be the only option. It’s in beta, so clearly isn’t finished.
The users are not de-anonymized, they use a ZKP transaction (https://en.wikipedia.org/wiki/Zero-knowledge_proof). We don’t need to have to trust Google, it’s the whole point of a zero trust model. Zero trust is required
When I talk about de-anonymizing the user, I mean that Google Play has already identified the user of the device. Then they can spy on the Signal app to try to identify the Signal account.
But also, regarding ZKP, afaik their ZKP doesn’t account for timing attacks. Signal can log when each account was made, and collude with Google to figure out which payments correspond to which accounts
I have never trusted them, I always considered many of Signal’s decisions highly questionable, and I think they are either pressured into them by the US government, cooperating in what they think are limited and carefully-implemented ways while claiming and perhaps even believing they are fighting the good fight, or maybe they are just a psyop honeypot to begin with. I cannot trust them, and if they truly wanted me to, they would not do so many things that require me to trust them.
And if it does support gift cards and prepaid cards?
This seems to me like a mild annoyance for someone using it legitimately, but a bigger barrier for scammers trying to get accounts in bulk. Sure they can get a lot of accounts still, but it’ll no doubt be lessened.
If they were going to do that they would not have just made an announcement about google pay’s “zero knowledge proofs” being the only way to pay it.
It becomes more than a mild annoyance it becomes borderline suspicious to be quite honest. None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.
Idk man. The phone number thing I could kind of understand but now the only way around it is a google pay payment? What the fuck is that? The fact that they won’t even accept their “super private” shitcoin is a huge red flag here to be completely honest. Just gonna call a spade a spade. Its a very strange choice from a privacy oriented service.
Its like using the Tor browser or something but you have to do a “zero knowledge proof” payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?
It’s weird.
Their original post says this:
I do not think this is suspicious. They are starting where most of their users are, and whether we like it or not, is play services.
Their implementation with play services seems to be correct if it were done for privacy, though we can’t ignore the fact it’s still supporting Google.
Nobody uses this. Signal also never processes a card. You have to transfer money from another crypto. That is not user friendly, and people would be pissed about this implementation too.
The open source decentralized projects? Those a great, and important, but they are different. Signal is balancing security with convenience. Most average people would give up the moment it asked for an instance. Signal is easy to use, even for the tech illiterate. It works just like their other messaging apps, but only because it’s centralized.
It’s about where the users are. Most tor users are going to be on a desktop device, probably Linux, maybe Windows, then everything else. A very small percentage are going to be on Android. It would be very weird to be on a Linux device in a Tor browser being sent to Google services for payment. Signal is a mobile messaging app, which means basically two ecosystems. I assume they started with play services because of number of users and/or the fact Google already had ZKP payment as an option.
And ZKP isn’t new, and it is real, and it’s exactly how more things should be implemented.
Look at how many scammers use WhatsApp, and how much spam there is. Signal is clearly trying to make it tje best user experience they can without compromising security. This is just one step further, and it’s only the first payment method, not the last.
But why not also accept crypto, like Bitcoin? That way actual privacy conscious people can just convert monero to bitcoin for a trustworthy decentralized private payment
The way I see it, that’s next. This feature is in beta, and I imagine they wanted to rollout the payment method that would be most used, or maybe easiest to implement first for testing. They have already officially said more payment methods will come, but they have not said what those payment methods will be. Given they already have their own crypto, that will almost definitely be one of the options
“That’s next” given that it took them years to make phone # optional, I’m not optimistic that this will happen anytime soon. Not to mention their current payment method requires play services, which has probably already de-anonymized the user
It tooks years to implement the whole functionality. They also weren’t working on this feature the whole time, but it was on the list. Adding another payment method isn’t the same.
I agree it’s not great to require play services, but it isn’t going to always be the only option. It’s in beta, so clearly isn’t finished.
The users are not de-anonymized, they use a ZKP transaction (https://en.wikipedia.org/wiki/Zero-knowledge_proof). We don’t need to have to trust Google, it’s the whole point of a zero trust model. Zero trust is required
When I talk about de-anonymizing the user, I mean that Google Play has already identified the user of the device. Then they can spy on the Signal app to try to identify the Signal account.
But also, regarding ZKP, afaik their ZKP doesn’t account for timing attacks. Signal can log when each account was made, and collude with Google to figure out which payments correspond to which accounts
Also, is that supposedly ZKP payment method something verified, audited and, more important, open sourced? It’s Google, so I’m 101% that no.
I have never trusted them, I always considered many of Signal’s decisions highly questionable, and I think they are either pressured into them by the US government, cooperating in what they think are limited and carefully-implemented ways while claiming and perhaps even believing they are fighting the good fight, or maybe they are just a psyop honeypot to begin with. I cannot trust them, and if they truly wanted me to, they would not do so many things that require me to trust them.