Comment by opengrass

1 day ago

Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.

It says something about Play Billing being used specifically to mitigate spam?

I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.

Ah OK, I wondered where is the "catch".

You cannot keep all 3 of "no gatekeeping" - "anyone can message anyone" - "low spam".

Ugh wtf so I need a Google account on Android? That's not going to happen.

For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.

Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

  • > Just allow monero payments or something.

    This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

    • > If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

      How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.

      Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device

    • Wouldn't a payment of about $0.05 do the trick? My understanding of most kinds of spam is that it relies on being able to deploy hundreds of thousands of bot accounts just to get a few hits.

      1 reply →

  • Are you being hyperbolic, or do you really consider Google the worst with regards to privacy.

    • The most ubiquitous, absolutely. Their data collection is unparalleled. They're on almost every website, app, they have fingers into payment and browsers and mobile OSes.

      In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.

  • googles obligation to hand out all account linked info notwithstanding, one may still create google accounts without associating a phone number, by doing so on old android versions. signal does however explicitly force credit card info here, thus providing direct individual traceability ..

What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.

  • Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.

    They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.

    • I always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.

  • True, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.

  • I've literally never seen anybody mention it, much less use it since it was announced.