Registration without a phone number on Signal will use zero-knowledge proofs

219 points - yesterday at 9:47 PM

Source

Comments

ggm today at 12:19 AM
For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.
purpleidea today at 12:23 AM
Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
opengrass today at 12:12 AM
Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
rkagerer today at 12:06 AM
Lots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?
ynniv today at 12:06 AM
you can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful
sysguest today at 3:44 AM
any link to presentations/papers on this?

I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much

Cider9986 today at 1:18 AM
I'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.
smalltorch today at 12:51 AM
The commit history is kinda wild
2Gkashmiri today at 2:10 AM
I know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems.

https://timesofindia.indiatimes.com/india/ats-probes-use-of-...

https://www.aninews.in/news/national/general-news/accused-da...

https://www.deccanherald.com/india/secure-messaging-apps-lik...

https://india-employmentnews.com/tech-category/delhi-blast-n...

https://timesofindia.indiatimes.com/tech-news/Dangerous-Sign...

And it doesn't matter you use a connected phone or not, they just get data from ISPs.

And yes, using a VPN will get you knocked up as well.

https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-k...

locitra today at 6:37 AM
[flagged]
victorbvieira today at 1:36 AM
[flagged]
user3939382 today at 12:14 AM
I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
atiq-ca yesterday at 11:25 PM
Signal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.