2 ms·
Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
by opengrass 13d ago
Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
- mmooss 13d agoWhat about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.
- Cider9986 13d agoNobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal. They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.
- wolvoleo 13d agoI always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.
- dakolli 12d agoThey avoid Monero because Signal and the EFF are actually the feds and this is all theater.
- Cider9986 12d agoClaims without evidence can be dismissed without evidence. Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX. If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised? They are the largest messenger that has E2EE backups by default.
- Jhater 12d ago[dead]
- monocasa 12d agoIf I was the NSA, I would be using the fact that signal uses AWS for their backend combined with the cudgel that .us.gov has with the AWS govcloud contract to mandate that all traffic to and from signal's backend also gets routed to NSA traffic analysis servers, which could then be correlated with other sources like ISP data to get a pretty complete record of all Signal message metadata. To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.
- dakolli 12d agoNobody is arguing the e2ee isn't valid, its useful as a metadata collection platform, which is all they care about. Former NSA and CIA Director Michael Hayden famously stated: “We kill people based on metadata." and then he tried to hold back a smile and said "but not with this metadata". It's usefulness as a metadata collection platform becomes much less useful if people don't trust it, so of course it's secure. If you can convince as many of your enemies (the american people who politically organize against them) to use the same platform, your job becomes easier than having to ETL from 20 different privacy platforms.. To be honest, I use signal, I have nothing to hide but it is useful in that nobody can spoof me (easily). I even talk to my 60 year old mother on signal. It has it's uses. But the EFF is definitely a federal psyop to get people using tools and techniques they control. Just look at the people who created TOR, they're all feds. All these projects are funded by feds. These tools are advertised in CIA recruitment campaigns, they are literal weapons to circumvent nation state firewalls and deliver psychological weapons, overthrow governments or allow covert recruitment of foreign traitors.
- thecrash 12d agoI'll see your conspiracy theory and raise you one: What if the feds fund tech privacy projects specifically so that people like you won't trust them, and instead embrace privacy nihilism? This is a known strategy of the Kremlin, by the way. They fund opposition groups which protest them, and then leak the fact of that funding so that people who are genuinely upset at the Kremlin get confused about who is captured opposition and who is legitimate. It can be a signal in some cases, but funding sources are not a reliable way to make a conclusion about a group's motivations.
- drum55 13d agoI've literally never seen anybody mention it, much less use it since it was announced.
- deleted 13d ago[deleted]
- wolvoleo 12d agoTrue, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.
- Cider9986 13d agoIt says something about Play Billing being used specifically to mitigate spam? I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.
- deleted 13d ago[deleted]
- opengrass 13d agoAdd ability to pay for a signal login. https://github.com/signalapp/Signal-Android/commit/7da3357b564b1d8b522710b30afbce184137f65d https://github.com/signalapp/Signal-Android/commit/7da3357b5...
- wolvoleo 13d agoUgh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.
- Cider9986 13d agoHopefully they eventually make a way to pay without it.
- genrader 13d agoYou wouldn't believe the spam if they did that
- Cider9986 13d agoWhy? Just raise the prices if they get more spam on non-google payments. I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.
- thin_carapace 13d agogoogles obligation to hand out all account linked info notwithstanding, one may still create google accounts without associating a phone number, by doing so on old android versions. signal does however explicitly force credit card info here, thus providing direct individual traceability ..
- wolvoleo 12d agoPlus they are mandating you give your details to Google. So much for privacy
- HWR_14 12d agoAre you being hyperbolic, or do you really consider Google the worst with regards to privacy.
- karel-3d 12d agoAh OK, I wondered where is the "catch". You cannot keep all 3 of "no gatekeeping" - "anyone can message anyone" - "low spam".