• hirihit640@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    11 hours ago

    But why not also accept crypto, like Bitcoin? That way actual privacy conscious people can just convert monero to bitcoin for a trustworthy decentralized private payment

    • Bazoogle@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      11 hours ago

      The way I see it, that’s next. This feature is in beta, and I imagine they wanted to rollout the payment method that would be most used, or maybe easiest to implement first for testing. They have already officially said more payment methods will come, but they have not said what those payment methods will be. Given they already have their own crypto, that will almost definitely be one of the options

      • hirihit640@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        10 hours ago

        “That’s next” given that it took them years to make phone # optional, I’m not optimistic that this will happen anytime soon. Not to mention their current payment method requires play services, which has probably already de-anonymized the user

        • Bazoogle@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          9 hours ago

          It tooks years to implement the whole functionality. They also weren’t working on this feature the whole time, but it was on the list. Adding another payment method isn’t the same.

          Not to mention their current payment method requires play services, which has probably already de-anonymized the user

          I agree it’s not great to require play services, but it isn’t going to always be the only option. It’s in beta, so clearly isn’t finished.

          The users are not de-anonymized, they use a ZKP transaction (https://en.wikipedia.org/wiki/Zero-knowledge_proof). We don’t need to have to trust Google, it’s the whole point of a zero trust model. Zero trust is required

          • hirihit640@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            9 hours ago

            When I talk about de-anonymizing the user, I mean that Google Play has already identified the user of the device. Then they can spy on the Signal app to try to identify the Signal account.

            But also, regarding ZKP, afaik their ZKP doesn’t account for timing attacks. Signal can log when each account was made, and collude with Google to figure out which payments correspond to which accounts

            • Kangae_Hishiryo@scribe.disroot.org
              link
              fedilink
              English
              arrow-up
              2
              ·
              4 hours ago

              Also, is that supposedly ZKP payment method something verified, audited and, more important, open sourced? It’s Google, so I’m 101% that no.