Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Definitely reasonable but the ultra privacy-conscious/paranoid can't easily donate or pay privately.


Sure, but privacy isn't black or white. A donation to signal does not compromise the content of your messaging.

So what you've leaked is the information that you have an interest in private conversations. This might be a problem in some countries, but I think it's fair to ask folks in affluent countries with working (sorta) democracies to shoulder that burden. I.e. you don't donate if there's elevated threat to your safety, there are enough people who aren't under elevated threat.

There's also the possibility of using a donation mixer like Silent Donor, though I'd evaluate that very carefully. (There's a record of the transfer in, and the mixer needs to keep temporary records for transferring out. There's also the question how you verify the mixer doesn't skim.)

Some donation mixers accept crypto currency, so for maximum paranoia, I suppose crypto->crypto mixer->donation mixer->charity might be workable. Or hand cash to a friend who donates in your stead.

As always, the best path is to set aside paranoia and build a threat model instead to see what the actual risks are.


There's never enough talk like this and I'm not sure why. It's always about the threat model. In this respect I always like to think of it in terms of probability. Probabilities and likelihoods aren't just about capturing randomness like quantum fluctuations or rolling dice, they are fundamentally about capturing uncertainty. Your threat model is your conditions and you can only calculate likelihoods as you don't know everything. There are no guarantees of privacy or security. This is why I always hated the conversations around when Signal was discussing deleting messages and people were saying that it's useless because someone could have saved the message before you deleted them. But this is also standard practice in industry because they understand the probabilistic framework and that there's a good chance that you delete before they save. Framing privacy and security as binary/deterministic options doesn't just do a poor but "good enough approximation" of these but actually leads you to make decisions that would decrease your privacy and security!

It's like brute forcing, we just want something where we'd be surprised if someone could accomplish it within the lifetime of the universe though technically it is possible for them to get it on the very first try if they are very very lucky. Which is an extreme understatement. It's far more likely that you could walk up to a random door, put the wrong key in, have the door's lock fall out of place, and open it to find a bear, a methhead, and a Rabbi sitting around a table drinking tea, playing cards, and the Rabbi has a full house. I'll take my odds on 256 bit encryption.


They take checks by mail. You definitely can do a cashier's check and I'm sure they'd take the "cash in an envelope" method that places like Mullvad do too. Looks like they also support crypto, and that includes Zcash. So I don't think this is a great excuse. The only "can't easily donate" aspect is going to also be tied with the "can't easily get a cashier's check or find an anonymous person to sell me bitcoin for cash" kinda issues, and when you're operating at that level I'm not sure anything is "easy." (but that's not that hard usually)

https://support.signal.org/hc/en-us/articles/360031949872-Do...


How is a check in any way private? Your name is on it.


A cashier's check doesn't.


Ah ok I didn't know those still existed. In fact even the named checks are long gone here in Europe lol.


Oh yeah, I have an old checkbook that I've had since like 2010 because the only ones I've ever used are for random landlords. Otherwise it's literally easier to get a cashier's check, which you can (in America) do at any bank or grocery store. Note that some are free and some aren't, so check beforehand. I don't think these will ever really go away tbh


I think they will, America is just very traditional. Things tend to stick around for longer. The magstripe also lingers there even though we've got rid of it for years (though unfortunately our cards still have them in case we need to visit the US - I don't like having them because they are skimmable).

Nobody would accept a check here anyway as they're not guaranteed. These days I pay with my watch or phone everywhere (Samsung Pay). I don't even use the chip on my card anymore. And payments between people happen digitally too (a system called Bizum here in Spain).


Maybe, but these some big utility to cashier's checks. They're essentially cash that can only be deposited by a specific party. I also don't think cash is going away anytime soon. And while it isn't common for me to issue a check, it isn't uncommon to receive a check. They're just always form businesses. Even ones that have my direct deposit information.

Fwiw, in America I use my phone to pay for everything too. But there are edge cases and tools like these often have utilities in domains that might not be common to the average person but are to specific groups. For example, these are often used in situations where cash is preferable but you wouldn't want to cary that around, like real estate down payments and buying a car. Some settings are sensitive to the exchange times (though that money looks like it is in your account instantly, it isn't).

I just wouldn't be so quick to make such a conclusion because it's pretty likely that your experience is not general. Despite America treating corporations like people, I'm pretty confident you aren't a corporation.

> Nobody would accept a check here anyway as they're not guaranteed.

Btw, a cashier's check is. Like I said, it is as good as cash.


Have you considered intentionally corrupting the magstripe data by running a strong magnet over it?


Hi, privacy and anonymity are different things. Named transactions can still be private.


There are clever ways around that. I use posteo as my mailprovider. They have a system where you can pay anonymously: https://posteo.de/en/site/payment


Signal requires a real phone number to open an account, you are not anonymous to Signal.


I can pop into almost any phone shop around here and walk out with a free SIM card, which I can top up for cash.


Phone numbers can be obtained anonymously in many countries. I have several anonymous Signal accounts, each with their own anonymous phone number.


It's possible in the US, but it's getting very difficult. I don't know anywhere you can buy or or borrow a DID with Monero anymore. Looks like they got to Telnum recently.

You can still buy a SIM, a prepaid PIN, and a phone with cash, but you'd need to pay a non-correlated person to be seen on CCTV to do it, at a non-correlated time, and hope they don't just take your money and leave you nothing at the dead drop.

Then there's the hassle of setting up the account in a way that's not correlated with your location, normal waking hours, etc.

All of this could just be avoided if Signal did the right thing.

But they won't. Ask yourself why.


Why would you not need to be seen on CCTV? This has nothing to do with the privacy of Signal.

I buy all of my anonymous prepaid SIMs with cash at retail myself, and they are still anonymous.

The only time you’d need to stay off CCTV is if you were using them to commit crimes and expected a significant investigation to be undertaken.

Your casual assertion of malice on the part of Signal is not supported by any facts.


Why are you typing my comments?

Exactly. They won't because .... reasons.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: