5 ms·
Registration without a phone number on Signal will use zero-knowledge proofs
- atiq-ca 12d agoSignal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.
- ranger_danger 12d agoI tried it and it was fine while it worked, but eventually I had to go back to regular Signal because Molly's updates did not follow Signal's closely enough, and at some point the server code changed enough to where I was unable to use it for an unacceptable amount of time (after checking, it took them weeks to update). Something to keep in mind if you're not using a custom server.
- blfr 12d agoMaybe it's because I use Molly as a secondary device (my tablet) but I never had an issue where it didn't work for weeks.
- Cider9986 12d agoMolly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal. In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush. I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it.. Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.
- rkagerer 12d agoIf you're using WebSocket, how do Google and Apple see metadata? Can someone explain why it's so difficult to make a decent chat app divorced from their ecosystems?
- Cider9986 12d agoI'm talking about using play services or Apple's version. Signal falls back to a WebSocket if you don't have play services installed.
- throwaway35435 12d ago[dead]
- john01dav 12d agoThe native Signal android app delivers notifications just fine without Google play services on my degoogled android.
- twothreeone 12d agoSame!
- opan 12d agoI was using Silence from F-Droid for a while back in the day because of these issues, but the lack of interop and needing to make everyone move again soured me on the whole thing. I would rather just get people on XMPP or Matrix and not use some sketchy phone-first app at all. For SMS I use Fossify Messages, which I think was a fork of QKSMS. I don't use SMS as primary or sensitive comms, only as needed. Same as email, basically, but less useful.
- nosioptar 12d agoI really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found. (I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)
- Cider9986 12d agoGrapheneOS is more well-roundedly private than any desktop OS. Competition is Qubes but that has usability issues and does not have good hardware security.
- nosioptar 12d agoI'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.
- Cider9986 12d agoThat's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want. Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation. It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration). You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services. Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-pixel-thread/7 https://discuss.grapheneos.org/d/10150-not-your-average-why-...
- flaburgan 12d agoCan you point where Signal uses proprietary blobs? Also, I'm using Signal without the play services notifications just fine. Notifications that don't contain any message content while transiting anyway. The display of the notification was the issue with iOS bug and that would have affected molly as well (if it was on iOS).
- rkagerer 12d agoLots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?
- Cider9986 12d agoLikely soon.
- blitzar 12d agoBy the end of the year (tm)
- commandersaki 12d agoSome say in this thread that it's supported by Google Play, but no mention of Apple's OSes, so I wonder if you can only do it on one platform.
- ynniv 12d agoyou can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful
- teravor 12d agousually, the implication of ZKP is that you buy coupons and claim them without attribution. in this coupon scenario the ZKP can just be a blind signature scheme. however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.
- blfr 12d agoThe fondness for TEEs is mostly Moxie's and I think he's not involved with Signal anymore. But he does have an AI chat/inference based on enclaves! https://confer.to/blog/2026/09/confidential-workers-for-private-ai/ https://confer.to/blog/2026/09/confidential-workers-for-priv...
- tornado134 12d ago[dead]
- opengrass 12d agoPer the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
- mmooss 12d agoWhat about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.
- Cider9986 12d agoNobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal. They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.
- wolvoleo 12d agoI always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.
- dakolli 12d agoThey avoid Monero because Signal and the EFF are actually the feds and this is all theater.
- Cider9986 12d agoClaims without evidence can be dismissed without evidence. Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX. If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised? They are the largest messenger that has E2EE backups by default.
- user3939382 12d agoI don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
- bawolff 12d agoViewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
- mitxela 12d agoWhatsApp is also sufficient for the average person. So is SMS. But they're not even slightly secure.
- bawolff 12d agoThe average person might be legit worried about dragnet (non targeted) evensdropping of non encrypted communication. This is rational given what Snowden said. So for the average person, WhatsApp (which is E2E encrypted) is probably quite secure. SMS is not.
- mitxela 10d agoBoth of them are dragnet surveilled. WhatsApp is theorised to do this through its automatic weekly backups.
- latentsea 12d ago>Figure out your adversaries, how much power they have and what they are willing to spend. All of it.
- ggm 12d agoFor those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.
- opengrass 12d agoYou can already do that without being a trusted device.
- ggm 12d agoFor the longest time, you couldn't. It wasn't until this release I realised that had changed. If it changed before, it wasn't well communicated to me as an Android signal user. I was on beeper and then molly precisely because there was so little traction on changing this. You could install signal fine, but you couldn't QR code or secret phrase mesh it with your android handset. Oddly, iPad meshed fine with iPhone or Android, and OSX desktop likewise. Just Android tablet which didn't. Do you think this changed in over 18 months? I think it changed in under 18 months.
- stavros 12d agoI think this is pretty recent, I'd never heard of it before. I even got a new phone a month ago and didn't notice this being an option.
- deleted 12d ago[deleted]
- msdz 12d agoDefinitely under 18 months. If I’m not fully mistaken, I checked for the combination of iPhone as main device/Android tablet as iPad-like second device sometime in the past six months, at most since the beginning of the year, and it wasn’t possible (unlike phone + iPad as tablet, which seemed quite strange to me). In any case, it’s a recently released change.
- purpleidea 12d agoSignal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
- s0ss 12d agoI’m not sure their tax status is the justification your argument needs.
- fsflover 12d agoIt's just an additional argument.
- deleted 12d ago[deleted]
- what 12d agoOpenAI is 501c3, should they also be required to release everything?
- alightsoul 12d agoYes
- gbriel 12d agoNon profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.
- akoboldfrying 12d agoPerhaps it shouldn't necessitate it, but I can't think of a good reason why not. If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day. Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason. What other reasons are there?
- smalltorch 12d agoThe commit history is kinda wild
- Cider9986 12d agoI'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.
- victorbvieira 12d ago[flagged]
- 2Gkashmiri 12d agoI know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems. https://timesofindia.indiatimes.com/india/ats-probes-use-of-signal-app-to-spread-anti-national-propaganda-fir-registered/articleshow/120461675.cms https://timesofindia.indiatimes.com/india/ats-probes-use-of-... https://www.aninews.in/news/national/general-news/accused-danish-used-signal-app-for-recruitment-radicalisation-fundraising-sources-on-suspected-isis-terrorist-arrested-in-ranchi20250920211208/ https://www.aninews.in/news/national/general-news/accused-da... https://www.deccanherald.com/india/secure-messaging-apps-like-signal-telegram-major-challenge-to-counter-online-radicalisation-centre-3313446 https://www.deccanherald.com/india/secure-messaging-apps-lik... https://india-employmentnews.com/tech-category/delhi-blast-not-whatsapp-terrorists-planned-the-entire/cid17809160.htm https://india-employmentnews.com/tech-category/delhi-blast-n... https://timesofindia.indiatimes.com/tech-news/Dangerous-Signal-This-encrypted-app-is-helping-ISIS-members-in-India-to-communicate/articleshow/51773877.cms https://timesofindia.indiatimes.com/tech-news/Dangerous-Sign... And it doesn't matter you use a connected phone or not, they just get data from ISPs. And yes, using a VPN will get you knocked up as well. https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-kashmir-adds-to-psychological-pressure-say-residents https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-k...
- Synthetic7346 12d ago[flagged]
- sysguest 12d agoany link to presentations/papers on this? I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much
- Cider9986 12d agonym.com might have some. They use stuff like that heavily and there's a bunch of academics involved. Also ZCash.
- jval43 12d agoIt's standard cryptography, not some new-fangled tech! Wikipedia even has some easy examples: https://en.wikipedia.org/wiki/Zero-knowledge_proof https://en.wikipedia.org/wiki/Zero-knowledge_proof Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%. Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straight up lie. Whether any application you run actually uses ZKP (or any other cryptography scheme) is unknown unless you have the source code.
- hasley 12d agoI liked this: "I can prove I’ve solved this Sudoku without revealing it" https://youtu.be/Otvcbw6k4eo https://youtu.be/Otvcbw6k4eo
- jmusall 12d agoHere's a site with a few (three) introductory articles on ZKPs: https://zkintro.com https://zkintro.com One in particular on pratical implementation of ZKPs was popular on HN back in 2024: https://zkintro.com/articles/programming-zkps-from-zero-to-hero https://zkintro.com/articles/programming-zkps-from-zero-to-h... (discussion at https://news.ycombinator.com/item?id=41398092 https://news.ycombinator.com/item?id=41398092)
- locitra 12d ago[flagged]
- hadlock 12d agoI stopped using signal when they made their weird change about not supporting SMS due to... whatever weird problem they had with normies. Come on dude. Even my realtor was on Signal. Instantly killed the product.
- sarjann 12d agoEspecially with AI agents being more common this would be very useful. I'd prefer to use Signal over telegram but haven't gotten around to getting another number.
- Sarkie 12d agoUnrelated. But if you have a spare phone with your account on, e.g. kids or whatever You can install Authenticator and get codes, even if the other phones need biometrics.
- npodbielski 12d agowhat would be the usecase? sharing account with kids? it is easier to just install something else and register on throwaway email?
- Piraty 12d agowake me up when signal can be used with no significant loss of feature or extra-hoops like signal-cli+SMS on non-google/non-apple devices like my linux desktops / linux phones.
- soltanov 12d agoDoes the protocol preserve its privacy benefit when payment, recovery, and anti-abuse metadata are considered together?
- voidnullvalue 12d agoConsidering the eyebrow raising funding sources, probably not
- BodyCulture 12d agoIs Signal still a trusted company in the industry? They are based in the USA.
- blfr 12d agoYes, very much so. It is basically a standard across the western world for politicians, journalists, whatsapp refugees... Of course there are many alternatives but most of them have most of their users here, on HN. MacOS, iOS, Windows, Linux, Android are all made in the US and are also virtually universally used. This idea that people avoid American products is super niche.
- macns 12d agoYes they're used all over the world but .. super niche? Have you been living under a rock? https://www.zdnet.com/article/europes-plan-to-ditch-us-tech-giants-is-built-on-open-source-and-its-gaining-steam/ https://www.zdnet.com/article/europes-plan-to-ditch-us-tech-... https://github.com/switch-to-eu/switch-to.eu https://github.com/switch-to-eu/switch-to.eu https://www.europeanswitch.com/why-european-providers/ https://www.europeanswitch.com/why-european-providers/ https://www.techspot.com/news/112362-europe-may-restrict-microsoft-amazon-google-handling-sensitive.html https://www.techspot.com/news/112362-europe-may-restrict-mic... https://www.independent.co.uk/news/world/europe/europe-zoom-teams-france-us-b2913584.html https://www.independent.co.uk/news/world/europe/europe-zoom-... linux us made in the US? An open source OS, with collaborators from all over the world initially started by a finnish student and still actively the main orchestrator of it, linux torvalds. Not to mention the thousand distros derived from it. https://en.wikipedia.org/wiki/Linux https://en.wikipedia.org/wiki/Linux PS: take this post as an opportunity to educate yourself rather than downvoting it.
- YPPH 12d agoCountry of origin doesn't tell you much on its own. Linux is American too, and few question its trustworthiness. What matters is the code being open source and auditable, not where the maintainers live.
- 12d ago
- douglee650 12d agoAhh yes, it is the technology that is the easiest gate to break down first. *takes puff on elaborately rare-wood pipe*
- evandraws 12d ago[flagged]
- user10235 12d agoWhat a headline! Meanwhile SimpleX and Delta Chat (over chatmail protocol) have it by default for years without any payment requirements, offer relatively better level of data security and are available on F-Droid main repo.
- DavideNL 12d agoI wish Delta Chat would have a more polished UI... the poor UI / design makes the app unappealing.
- EGreg 12d agoHow do they prevent sybil attacks and bots then?
- monkeetools 12d ago[dead]
- iamsyr 12d agoOnce phones are gone from signup, what do they use that attackers can’t mint cheaply?
- mr_big_bowls 11d agoYeah, ditching the phone number sounds good. But if the replacement is Google or payment info, then... did we really fix much? Kinda feels like trading one ID for another.
- PinkiesBrain 10d agoHow does ZKP keep payment data seperate from the account. You can add a payment reference to your payment in some kind of cryptographic protocol, but if it's not in their database you can't login and if it is you can. So completely identifiable? Some combination with TEE to act as a mixer with a time limited internal secret in the TEE sandbox for verification before converting it to a "paid" flag?
- PinkiesBrain 10d agoOr does the server send a block of payment references to the client, with the client giving a ZKP to prove "yep, one of those is mine"?