ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
55% Positive
Analyzed from 1124 words in the discussion.
Trending Topics
#signal#android#google#without#play#using#molly#phone#something#monero

Discussion (38 Comments)Read Original on HackerNews
Do you think this changed in over 18 months? I think it changed in under 18 months.
I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.
https://github.com/signalapp/Signal-Android/commit/7da3357b5...
For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.
Just allow monero payments or something. Alongside Google play for the sheep that want to use that.
They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.
however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.
I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?
While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.
I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.
In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.
I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..
Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.
(I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)
Competition is Qubes but that has usability issues and does not have good hardware security.