Registration without a phone number on Signal will use zero-knowledge proofs

249 pointsposted 11 hours ago
by Cider9986

40 Comments

ggm

9 hours ago

For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.

opengrass

9 hours ago

You can already do that without being a trusted device.

kroken

4 hours ago

Thanks for pointing this out. I've been waiting for this for years and was not aware!

purpleidea

9 hours ago

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

ezst

3 hours ago

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims about being privacy conscious.

s0ss

8 hours ago

I’m not sure their tax status is the justification your argument needs.

crossroadsguy

2 hours ago

Not only that. I also question how they pick new features to implement. For example usernames - I am not going to trust another "private" IM app username feature same as what Telegram and WhatsApp questionably chose. Compromise on this? Well, then even WhatsApp and Telegram are good enough with compromises.

Separate usernames completely from phone numbers. Period.

There's a reason Signal is still "US based". No, I am not talking about some CIA/NSA/DoD/tom/jerry funding conspiracy, just good old human obstinacy and hubris. They don't give a f about who uses it, it's about who makes and maintains it all.

what

6 hours ago

OpenAI is 501c3, should they also be required to release everything?

opengrass

9 hours ago

Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.

Cider9986

8 hours ago

It says something about Play Billing being used specifically to mitigate spam?

I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.

wolvoleo

8 hours ago

Ugh wtf so I need a Google account on Android? That's not going to happen.

For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.

Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

mmooss

9 hours ago

What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.

rkagerer

9 hours ago

Lots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?

blitzar

2 minutes ago

By the end of the year (tm)

ynniv

9 hours ago

you can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful

teravor

8 hours ago

usually, the implication of ZKP is that you buy coupons and claim them without attribution. in this coupon scenario the ZKP can just be a blind signature scheme.

however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.

sysguest

5 hours ago

any link to presentations/papers on this?

I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much

Cider9986

5 hours ago

nym.com might have some. They use stuff like that heavily and there's a bunch of academics involved.

Also ZCash.

jval43

4 hours ago

It's standard cryptography, not some new-fangled tech! Wikipedia even has some easy examples:

https://en.wikipedia.org/wiki/Zero-knowledge_proof

Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%.

Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straight up lie. Whether any application you run actually uses ZKP (or any other cryptography scheme) is unknown unless you have the source code.

hadlock

28 minutes ago

I stopped using signal when they made their weird change about not supporting SMS due to... whatever weird problem they had with normies. Come on dude. Even my realtor was on Signal. Instantly killed the product.

Cider9986

8 hours ago

I'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.

smalltorch

8 hours ago

The commit history is kinda wild

2Gkashmiri

7 hours ago

I know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems.

https://timesofindia.indiatimes.com/india/ats-probes-use-of-...

https://www.aninews.in/news/national/general-news/accused-da...

https://www.deccanherald.com/india/secure-messaging-apps-lik...

https://india-employmentnews.com/tech-category/delhi-blast-n...

https://timesofindia.indiatimes.com/tech-news/Dangerous-Sign...

And it doesn't matter you use a connected phone or not, they just get data from ISPs.

And yes, using a VPN will get you knocked up as well.

https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-k...

wolvoleo

7 hours ago

Yes that's bad but that's an Indian government problem, not a signal or other messenger app problem. And really, it sounds like there was a lot more going on with these people than just using a particular app. Discord and WhatsApp are mentioned too.

India also bans most satellite phones by the way. I have one so I looked into that as to not get caught out travelling.

sans_souse

2 hours ago

> And yes, using a VPN will get you knocked up as well.

Well, damn.

Cider9986

6 hours ago

And WhatsApp is E2EE with the same protocol so I don't see the big deal.

user3939382

9 hours ago

I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".

bawolff

9 hours ago

Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there.

I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

420official

9 hours ago

Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?

atiq-ca

10 hours ago

Signal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.

Cider9986

9 hours ago

Molly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal.

In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.

I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..

Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.

flaburgan

an hour ago

Can you point where Signal uses proprietary blobs? Also, I'm using Signal without the play services notifications just fine. Notifications that don't contain any message content while transiting anyway. The display of the notification was the issue with iOS bug and that would have affected molly as well (if it was on iOS).

john01dav

9 hours ago

The native Signal android app delivers notifications just fine without Google play services on my degoogled android.

opan

9 hours ago

I was using Silence from F-Droid for a while back in the day because of these issues, but the lack of interop and needing to make everyone move again soured me on the whole thing. I would rather just get people on XMPP or Matrix and not use some sketchy phone-first app at all. For SMS I use Fossify Messages, which I think was a fork of QKSMS. I don't use SMS as primary or sensitive comms, only as needed. Same as email, basically, but less useful.

ranger_danger

10 hours ago

I tried it and it was fine while it worked, but eventually I had to go back to regular Signal because Molly's updates did not follow Signal's closely enough, and at some point the server code changed enough to where I was unable to use it for an unacceptable amount of time (after checking, it took them weeks to update). Something to keep in mind if you're not using a custom server.