• Bazoogle@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    10 hours ago

    It tooks years to implement the whole functionality. They also weren’t working on this feature the whole time, but it was on the list. Adding another payment method isn’t the same.

    Not to mention their current payment method requires play services, which has probably already de-anonymized the user

    I agree it’s not great to require play services, but it isn’t going to always be the only option. It’s in beta, so clearly isn’t finished.

    The users are not de-anonymized, they use a ZKP transaction (https://en.wikipedia.org/wiki/Zero-knowledge_proof). We don’t need to have to trust Google, it’s the whole point of a zero trust model. Zero trust is required

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 hours ago

      When I talk about de-anonymizing the user, I mean that Google Play has already identified the user of the device. Then they can spy on the Signal app to try to identify the Signal account.

      But also, regarding ZKP, afaik their ZKP doesn’t account for timing attacks. Signal can log when each account was made, and collude with Google to figure out which payments correspond to which accounts

      • Kangae_Hishiryo@scribe.disroot.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 hours ago

        Also, is that supposedly ZKP payment method something verified, audited and, more important, open sourced? It’s Google, so I’m 101% that no.