post by kevino on Aug 22
i am sure there is a catch to it. I am not sure if zero knowledge proofs are used for this. So it cannot be gauranteed 100% to the user , specially at the time of first subscription. I think there is a difference between what usual practice signal choses to follow vs what signal can practically do at the server end without altering the client behaviour incase they were forced to do so or otherwise.
Not to forget, signal could always be subpeaned to keep metadata information relating to certain accounts.
post by rassilon1963 on Aug 22
you have legitimate concerns, but you’re very wrong about this. zero-knowledge proofs are not only the technology behind donation badges and backup payments, but also behind groups. they can’t tie you to a specific donation just like they can’t tie you to a specific group.
the great thing about Signal is the client is designed to already not trust the server. in fact you can show that Signal is perfectly safe without even looking at server code.
post by Avitus on Aug 26
post by alex-signal on Aug 26
ZKP is also used for verifying things like username character set and length without actually revealing contents which is super cool and comprises of math waaaayyyyy above my head.




