this post was submitted on 25 Sep 2026
310 points (97.8% liked)

Technology

88272 readers
3099 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] solrize@lemmy.ml 88 points 2 days ago (4 children)

You mean they want to identify you from your credit card instead of your phone number? Bah.

[–] empireOfLove2@lemmy.dbzer0.com 67 points 2 days ago (4 children)

They claim it's "zero knowledge" proof through Google pay, meaning that Google will know you paid Signal, and Signal knows you paid them, but there is no link between the two that uses your PII payment info to identify the Signal account. I'm inclined to believe them.

[–] Kangae_Hishiryo@scribe.disroot.org 5 points 1 day ago (1 children)

If they pass through Google infrastructure, then it's a no.

Also, why would you have to pay for something that should be a completely free and basic feature?

They're completely off the rails.

[–] DeadDigger@lemmy.zip 6 points 1 day ago (1 children)
[–] Kangae_Hishiryo@scribe.disroot.org 1 points 1 day ago* (last edited 1 day ago)

Lmao, it can be achieved in better ways; they can just use a ZKP FLOSS captcha (such as Anubis, but adapted for native apps, there are some), or manual verification (such as most XMPP or Matrix instances, and even more general online services providers such as Disroot [this one uses Anubis AND manual email verification for the signup process, then only Anubis]).

They're shady asf, and now are being exclusionary towards these who can't pay? Hell naw, fuck 'em

[–] WhoIzDisIz@lemmy.today 16 points 2 days ago* (last edited 2 days ago) (2 children)

Unless you wait a good while to use what you paid for (if that's even possible), then I doubt it'd be hard to connect the dots. Never mind connecting transaction records.

[–] LodeMike@lemmy.today 10 points 2 days ago (1 children)

It's the exact same privacy protection as signing up with a phone number.

[–] FridaVanMercury@discuss.tchncs.de 3 points 1 day ago (3 children)

Not quite. With a phone number a random phone provider knows your identity. They do not get notified you are signing up for Signals. Google doesn't know you signed up with that phone number for Signals either. Depending on your country and how these details are handled there may not be an easy way to lookup who you are from a phone number.

There's obvious downsides to the phone number use, of course, but saying it the same in terms of privacy than this, doesn't feel correct.

[–] LodeMike@lemmy.today 3 points 1 day ago* (last edited 1 day ago)

There's identical security for the payment too. Assuming you trust Signal, they don't keep a record of it tied to your actual account the same with a phone number.

[–] LodeMike@lemmy.today 1 points 1 day ago

"Your Signal code is..."

[–] LodeMike@lemmy.today 0 points 1 day ago

Oh, also, they're just using Google Play for now. They'll definitely be adding a generic CC option.

[–] Zedd_Prophecy@lemmy.world 4 points 2 days ago

Could use a refillable credit card.

[–] solrize@lemmy.ml 10 points 2 days ago (1 children)

Google will know you paid Signal

That's not ok either! Just stop playing these games and stop obstructing self hosting. When they come to round up all the Signal users, they won't care what account belongs to who. So there should be no database that identifies the users.

[–] daychilde@lemmy.world 15 points 2 days ago (1 children)

If "they" get to the point of rounding up all Signal users, not using Signal will not prevent you from being rounded up.

[–] 100_kg_90_de_belin@feddit.it 2 points 1 day ago

First they came for the Treema users...

[–] hirihit640@sh.itjust.works 8 points 2 days ago

If Google and Signal collude can they link payments to accounts via timing attacks? My guess is yes

[–] hummingbird@lemmy.world 2 points 1 day ago

It is almost as if they have no fucking clue who their customers are. Hilarious.

[–] Venator@lemmy.nz 10 points 2 days ago (4 children)

Could possibly use a gift card?

[–] faded_emulsion@lemmy.world 2 points 1 day ago

You can, I was able to sign up on a tablet running Lineage OS with GApps that had credit loaded from a Play Gift Card

[–] DanceMomsSavedMe@lemmy.zip 18 points 2 days ago* (last edited 2 days ago) (4 children)

I'll call it right now and bet they want 3DS supported cards. So no giftcards and no prepaid cards.

I use signal all the time but even I will admit some of the things they do don't scream privacy conscious to me. This is one of those things.

For instance, no support for their shitty crypto no one ever uses? You know, the one they chose over an actual battle tested one like Monero? (Its basically a pump and dump, look at the all time chart on coingecko for Mobilecoin went from like $50 a coin to 0.07¢ now)

Nope. Just traceable cards or traceable phone numbers. Interesting choice. The lack of self hosting is also an interesting choice.

Way better than Telegram or Facebook or WhatsApp for sure for sure and I get all my friends to use signal but I do have doubts sometimes when I start to notice stuff like this.

People will get on here and say "only FEDS promote fud about signal!!" But honestly ask yourself if what you just read really aligns with privacy in any way. A lot of it does not.

Even the same people who hate crypto actively use signal which did its own pump and dump scheme. Its odd. And I wish an actual competitor would come out that isn't based in another surveillance state like the UK.

Literally all the alternatives are from surveillance States. Every single one. All of them.

Idk man, I have doubts a lot.

[–] Bazoogle@lemmy.world 6 points 2 days ago (1 children)

And if it does support gift cards and prepaid cards?

This seems to me like a mild annoyance for someone using it legitimately, but a bigger barrier for scammers trying to get accounts in bulk. Sure they can get a lot of accounts still, but it'll no doubt be lessened.

[–] DanceMomsSavedMe@lemmy.zip 6 points 2 days ago* (last edited 2 days ago) (2 children)

If they were going to do that they would not have just made an announcement about google pay's "zero knowledge proofs" being the only way to pay it.

It becomes more than a mild annoyance it becomes borderline suspicious to be quite honest. None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.

Idk man. The phone number thing I could kind of understand but now the only way around it is a google pay payment? What the fuck is that? The fact that they won't even accept their "super private" shitcoin is a huge red flag here to be completely honest. Just gonna call a spade a spade. Its a very strange choice from a privacy oriented service.

Its like using the Tor browser or something but you have to do a "zero knowledge proof" payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?

It's weird.

[–] Bazoogle@lemmy.world 9 points 2 days ago (1 children)

Their original post says this:

Can I buy an account on a device that has no Play Services?

Not yet. We have plans to add more payment methods, but currently only offer Play Store in-app payments, which requires Play Services.

I do not think this is suspicious. They are starting where most of their users are, and whether we like it or not, is play services.

Their implementation with play services seems to be correct if it were done for privacy, though we can't ignore the fact it's still supporting Google.

The fact that they won’t even accept their “super private” shitcoin is a huge red flag here to be completely honest.

Nobody uses this. Signal also never processes a card. You have to transfer money from another crypto. That is not user friendly, and people would be pissed about this implementation too.

None of the other private app competitors have ever needed a phone number or payment and a lot of them let you self host too something signal is vehemently against.

The open source decentralized projects? Those a great, and important, but they are different. Signal is balancing security with convenience. Most average people would give up the moment it asked for an instance. Signal is easy to use, even for the tech illiterate. It works just like their other messaging apps, but only because it's centralized.

Its like using the Tor browser or something but you have to do a “zero knowledge proof” payment through google pay to access it. Would that make you feel comfortable? No? Then why are we acting like its ok for signal?

It's about where the users are. Most tor users are going to be on a desktop device, probably Linux, maybe Windows, then everything else. A very small percentage are going to be on Android. It would be very weird to be on a Linux device in a Tor browser being sent to Google services for payment. Signal is a mobile messaging app, which means basically two ecosystems. I assume they started with play services because of number of users and/or the fact Google already had ZKP payment as an option.

And ZKP isn't new, and it is real, and it's exactly how more things should be implemented.

Look at how many scammers use WhatsApp, and how much spam there is. Signal is clearly trying to make it tje best user experience they can without compromising security. This is just one step further, and it's only the first payment method, not the last.

[–] hirihit640@sh.itjust.works 2 points 2 days ago (1 children)

But why not also accept crypto, like Bitcoin? That way actual privacy conscious people can just convert monero to bitcoin for a trustworthy decentralized private payment

[–] Bazoogle@lemmy.world 3 points 2 days ago (1 children)

The way I see it, that's next. This feature is in beta, and I imagine they wanted to rollout the payment method that would be most used, or maybe easiest to implement first for testing. They have already officially said more payment methods will come, but they have not said what those payment methods will be. Given they already have their own crypto, that will almost definitely be one of the options

[–] hirihit640@sh.itjust.works 2 points 2 days ago (1 children)

"That's next" given that it took them years to make phone # optional, I'm not optimistic that this will happen anytime soon. Not to mention their current payment method requires play services, which has probably already de-anonymized the user

[–] Bazoogle@lemmy.world 2 points 2 days ago (1 children)

It tooks years to implement the whole functionality. They also weren't working on this feature the whole time, but it was on the list. Adding another payment method isn't the same.

Not to mention their current payment method requires play services, which has probably already de-anonymized the user

I agree it's not great to require play services, but it isn't going to always be the only option. It's in beta, so clearly isn't finished.

The users are not de-anonymized, they use a ZKP transaction (https://en.wikipedia.org/wiki/Zero-knowledge_proof). We don't need to have to trust Google, it's the whole point of a zero trust model. Zero trust is required

[–] hirihit640@sh.itjust.works 1 points 2 days ago (1 children)

When I talk about de-anonymizing the user, I mean that Google Play has already identified the user of the device. Then they can spy on the Signal app to try to identify the Signal account.

But also, regarding ZKP, afaik their ZKP doesn't account for timing attacks. Signal can log when each account was made, and collude with Google to figure out which payments correspond to which accounts

Also, is that supposedly ZKP payment method something verified, audited and, more important, open sourced? It's Google, so I'm 101% that no.

[–] cecilkorik@lemmy.ca 3 points 2 days ago

I have never trusted them, I always considered many of Signal's decisions highly questionable, and I think they are either pressured into them by the US government, cooperating in what they think are limited and carefully-implemented ways while claiming and perhaps even believing they are fighting the good fight, or maybe they are just a psyop honeypot to begin with. I cannot trust them, and if they truly wanted me to, they would not do so many things that require me to trust them.

[–] wreckedcarzz@lemmy.world 3 points 2 days ago

Smh, now I have to get a Nintendo credit card?

(if you don't get it, read the above comment again)

[–] billbasher@lemmy.world 1 points 1 day ago

I miss Wikr before it enshittified

[–] AHemlocksLie@lemmy.zip 3 points 2 days ago

Yeah... Combine all that with being based in the US under the fascistic Trump admin, and I'm considering trying to get my friends and family to swap to a self-hosted XMPP server or something, but there are a couple elderly relatives that might complicate that.

[–] solrize@lemmy.ml 3 points 2 days ago

IDK maybe that's possible but I'd rather avoid Signal, except maybe for a self hosted fork.

[–] Imgonnatrythis@sh.itjust.works 2 points 2 days ago* (last edited 2 days ago)

Very few online services accept. I'll eat my hat if I'm wrong and hell I'll sign up with one if they take them, but I sincerely doubt they will accept these.

[–] Crumpled6273@lemmy.ca 2 points 2 days ago

Not me. But the author.