you are viewing a single comment's thread
view the rest of the comments
[–] 68 points 5 days ago (14 children)

They claim it's "zero knowledge" proof through Google pay, meaning that Google will know you paid Signal, and Signal knows you paid them, but there is no link between the two that uses your PII payment info to identify the Signal account. I'm inclined to believe them.

  • source
  • parent
  • hideshow 14 child comments
  • [–] 16 points 5 days ago* (6 children)

    Unless you wait a good while to use what you paid for (if that's even possible), then I doubt it'd be hard to connect the dots. Never mind connecting transaction records.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 10 points 5 days ago (4 children)

    It's the exact same privacy protection as signing up with a phone number.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 3 points 4 days ago (3 children)

    Not quite. With a phone number a random phone provider knows your identity. They do not get notified you are signing up for Signals. Google doesn't know you signed up with that phone number for Signals either. Depending on your country and how these details are handled there may not be an easy way to lookup who you are from a phone number.

    There's obvious downsides to the phone number use, of course, but saying it the same in terms of privacy than this, doesn't feel correct.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 4 days ago* (last edited 4 days ago)

    There's identical security for the payment too. Assuming you trust Signal, they don't keep a record of it tied to your actual account the same with a phone number.

  • source
  • parent
  • [–] 10 points 5 days ago (2 children)

    Google will know you paid Signal

    That's not ok either! Just stop playing these games and stop obstructing self hosting. When they come to round up all the Signal users, they won't care what account belongs to who. So there should be no database that identifies the users.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 4 days ago (2 children)

    If they pass through Google infrastructure, then it's a no.

    Also, why would you have to pay for something that should be a completely free and basic feature?

    They're completely off the rails.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 4 days ago (1 child)
  • [–] 1 point 4 days ago* (last edited 4 days ago)

    Lmao, it can be achieved in better ways; they can just use a ZKP FLOSS captcha (such as Anubis, but adapted for native apps, there are some), or manual verification (such as most XMPP or Matrix instances, and even more general online services providers such as Disroot [this one uses Anubis AND manual email verification for the signup process, then only Anubis]).

    They're shady asf, and now are being exclusionary towards these who can't pay? Hell naw, fuck 'em

  • source
  • parent