Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

151–160 of 208 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#152

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

Why do you want infra automation code?

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#153

Is Signal still a trusted company in the industry? They are based in the USA.

Yes, very much so. It is basically a standard across the western world for politicians, journalists, whatsapp refugees... Of course there are many alternatives but most of them have most of their users here, on HN.

MacOS, iOS, Windows, Linux, Android are all made in the US and are also virtually universally used. This idea that people avoid American products is super niche.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#154

Is Signal still a trusted company in the industry? They are based in the USA.

Country of origin doesn't tell you much on its own. Linux is American too, and few question its trustworthiness. What matters is the code being open source and auditable, not where the maintainers live.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#156
post #37
post #9

you can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful

usually, the implication of ZKP is that you buy coupons and claim them without attribution. in this coupon scenario the ZKP can just be a blind signature scheme. however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.

The fondness for TEEs is mostly Moxie's and I think he's not involved with Signal anymore. But he does have an AI chat/inference based on enclaves!

https://confer.to/blog/2026/09/confidential-workers-for-priv...

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#157
post #99

Earlier quoted context omitted.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…

Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

(Note that I don't care about cryptocurrencies except for the cryptography behind it)

There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).

If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.

But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".

I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#158
post #68

Earlier quoted context omitted.

Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.

> Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have. Actually you're mistaken. Under the 501(c)(3) tax code rules, they are required to act in the public good. Nobody has sued them to enforce this though, but I'd at least like them to acknowledge the game they're playing by…

American 501c3 law is extremely lax compared to analogous structures in the EU. A number of 501c3s are run as sinecures where a board (self-selecting, so no input from the membership) just hires its friends for well-paid positions that involve little work. Because the law is so lax and permissive, making a case that a given org is not acting in the public good is extremely rare and uphill.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#159

Lots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?

Some say in this thread that it's supported by Google Play, but no mention of Apple's OSes, so I wonder if you can only do it on one platform.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#160

Earlier quoted context omitted.

Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers). For most people and use cases, either will pro…

> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal

So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?

I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ?

Some would label Signal as a honeypot and it would be difficult to falsify that.

Post reply on HN