\

Registration without a phone number on Signal will use zero-knowledge proofs

107 points - yesterday at 9:47 PM

Source
  • ggm

    today at 12:19 AM

    For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.

      • Cider9986

        today at 1:39 AM

        Here's an article saying that: https://aboutsignal.com/news/signal-allows-android-phones-to...

        • opengrass

          today at 12:25 AM

          You can already do that without being a trusted device.

            • ggm

              today at 12:52 AM

              For the longest time, you couldn't. It wasn't until this release I realised that had changed. If it changed before, it wasn't well communicated to me as an Android signal user. I was on beeper and then molly precisely because there was so little traction on changing this. You could install signal fine, but you couldn't QR code or secret phrase mesh it with your android handset. Oddly, iPad meshed fine with iPhone or Android, and OSX desktop likewise. Just Android tablet which didn't.

              Do you think this changed in over 18 months? I think it changed in under 18 months.

      • opengrass

        today at 12:12 AM

        Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.

          • Cider9986

            today at 12:39 AM

            It says something about Play Billing being used specifically to mitigate spam?

            I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.

          • wolvoleo

            today at 1:17 AM

            Ugh wtf so I need a Google account on Android? That's not going to happen.

            For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.

            Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

              • Cider9986

                today at 1:19 AM

                Hopefully they eventually make a way to pay without it.

                  • genrader

                    today at 1:28 AM

                    You wouldn't believe the spam if they did that

                      • Cider9986

                        today at 1:36 AM

                        Why? Just raise the prices if they get more spam on non-google payments.

                        I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.

                • thin_carapace

                  today at 1:26 AM

                  googles obligation to hand out all account linked info notwithstanding, one may still create google accounts without associating a phone number, by doing so on old android versions. signal does however explicitly force credit card info here, thus providing direct individual traceability ..

                    • wolvoleo

                      today at 2:31 AM

                      Plus they are mandating you give your details to Google. So much for privacy

              • mmooss

                today at 12:22 AM

                What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.

                  • wolvoleo

                    today at 2:40 AM

                    True, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.

                    • Cider9986

                      today at 12:37 AM

                      Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.

                      They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.

                        • wolvoleo

                          today at 1:23 AM

                          I always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.

                          • dakolli

                            today at 2:38 AM

                            They avoid Monero because Signal and the EFF are actually the feds and this is all theater.

                              • Cider9986

                                today at 2:57 AM

                                Claims without evidence can be dismissed without evidence.

                                Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.

                                If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?

                                They are the largest messenger that has E2EE backups by default.

                        • drum55

                          today at 1:15 AM

                          I've literally never seen anybody mention it, much less use it since it was announced.

                            • today at 1:30 AM

                  • purpleidea

                    today at 12:23 AM

                    Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

                      • s0ss

                        today at 12:42 AM

                        I’m not sure their tax status is the justification your argument needs.

                        • today at 1:01 AM

                      • ynniv

                        today at 12:06 AM

                        you can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful

                          • teravor

                            today at 1:20 AM

                            usually, the implication of ZKP is that you buy coupons and claim them without attribution. in this coupon scenario the ZKP can just be a blind signature scheme.

                            however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.

                        • rkagerer

                          today at 12:06 AM

                          Lots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?

                            • Cider9986

                              today at 1:18 AM

                              Likely soon.

                          • Cider9986

                            today at 1:18 AM

                            I'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.

                            • smalltorch

                              today at 12:51 AM

                              The commit history is kinda wild

                              • 2Gkashmiri

                                today at 2:10 AM

                                I know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems.

                                https://timesofindia.indiatimes.com/india/ats-probes-use-of-...

                                https://www.aninews.in/news/national/general-news/accused-da...

                                https://www.deccanherald.com/india/secure-messaging-apps-lik...

                                https://india-employmentnews.com/tech-category/delhi-blast-n...

                                https://timesofindia.indiatimes.com/tech-news/Dangerous-Sign...

                                And it doesn't matter you use a connected phone or not, they just get data from ISPs.

                                And yes, using a VPN will get you knocked up as well.

                                https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-k...

                                  • Cider9986

                                    today at 3:02 AM

                                    [delayed]

                                    • wolvoleo

                                      today at 2:33 AM

                                      Yes that's bad but that's an Indian government problem, not a signal or other messenger app problem. And really, it sounds like there was a lot more going on with these people than just using a particular app. Discord and WhatsApp are mentioned too.

                                      India also bans most satellite phones by the way. I have one so I looked into that as to not get caught out travelling.

                                      • Synthetic7346

                                        today at 2:31 AM

                                        What if I use a VPN as a dude? Still gonna get knocked up?

                                          • wolvoleo

                                            today at 2:37 AM

                                            You will be if you drop the soap after you get arrested :)

                                    • victorbvieira

                                      today at 1:36 AM

                                      [flagged]

                                      • user3939382

                                        today at 12:14 AM

                                        I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".

                                          • bawolff

                                            today at 12:21 AM

                                            Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there.

                                            I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

                                            • 420official

                                              today at 12:28 AM

                                              Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

                                              I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?

                                                • mmooss

                                                  today at 12:35 AM

                                                  > Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

                                                  While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.

                                                  I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.

                                          • atiq-ca

                                            yesterday at 11:25 PM

                                            Signal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.

                                              • Cider9986

                                                yesterday at 11:52 PM

                                                Molly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal.

                                                In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.

                                                I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..

                                                Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.

                                                  • rkagerer

                                                    today at 12:02 AM

                                                    If you're using WebSocket, how do Google and Apple see metadata? Can someone explain why it's so difficult to make a decent chat app divorced from their ecosystems?

                                                      • Cider9986

                                                        today at 12:30 AM

                                                        I'm talking about using play services or Apple's version. Signal falls back to a WebSocket if you don't have play services installed.

                                                • john01dav

                                                  today at 12:03 AM

                                                  The native Signal android app delivers notifications just fine without Google play services on my degoogled android.

                                                  • opan

                                                    today at 12:08 AM

                                                    I was using Silence from F-Droid for a while back in the day because of these issues, but the lack of interop and needing to make everyone move again soured me on the whole thing. I would rather just get people on XMPP or Matrix and not use some sketchy phone-first app at all. For SMS I use Fossify Messages, which I think was a fork of QKSMS. I don't use SMS as primary or sensitive comms, only as needed. Same as email, basically, but less useful.

                                                      • nosioptar

                                                        today at 12:22 AM

                                                        I really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found.

                                                        (I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)

                                                          • Cider9986

                                                            today at 1:21 AM

                                                            GrapheneOS is more well-roundedly private than any desktop OS.

                                                            Competition is Qubes but that has usability issues and does not have good hardware security.

                                                              • wolvoleo

                                                                today at 2:36 AM

                                                                The problem for me is writing on a mobile device is a terrible user experience.

                                                                When I'm at home I don't wanna use a virtual keyboard on a 6.3" (or 7.9 unfolded). I just want to use my triple monitor PC setup with a real keyboard and a wealth of display space.

                                                                Mobile is cool for on the go but a productivity killer.

                                                                • nosioptar

                                                                  today at 1:36 AM

                                                                  I'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.

                                                                    • Cider9986

                                                                      today at 1:49 AM

                                                                      That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want.

                                                                      Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.

                                                                      It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).

                                                                      You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.

                                                                      Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-...

                                                      • ranger_danger

                                                        yesterday at 11:31 PM

                                                        I tried it and it was fine while it worked, but eventually I had to go back to regular Signal because Molly's updates did not follow Signal's closely enough, and at some point the server code changed enough to where I was unable to use it for an unacceptable amount of time (after checking, it took them weeks to update). Something to keep in mind if you're not using a custom server.

                                                          • blfr

                                                            yesterday at 11:54 PM

                                                            Maybe it's because I use Molly as a secondary device (my tablet) but I never had an issue where it didn't work for weeks.

                                                        • throwaway35435

                                                          today at 12:01 AM

                                                          [dead]