Systems like zcash and monero are similar: if you don't trust the cryptography then they're not useful, but it seems like a strange objection to say somebody could do unsavory things if they could break the cryptography, that's what it's for!
If the cafe, thief or anyone steals my money for whatever reason other than me physically giving someone my card/PIN then the bank or credit card company is legally responsible. And they will refund you the money.
Look forward to Web3 without a similar safety net in place.
The worry wouldn't be about someone breaking TLS, but someone MitM your connection with your card processor in a way you don't notice. One is much more likely than the other.
Generally what happens is that: - Everyone is able to prove a transaction's correctness; - There's no way for a third party to track the contents of a transaction adversarialy; - there are ways for first and second parties to prove them if they so wish.
Cryptography ensures that transaction amounts, sender, receiver are encrypted. There is no way to decrypt the data. You can verify the encrypted data without decrypting it. Everything works similar to Bitcoin but now you and others have no way of figuring out anything valuable by looking at the blockchain, because everything on the blockchain is just encrypted bytes.
Even the node that is the first one to receive all bytes has no idea who is sending, receiving and the amount. Everything is always encrypted.
When I create a transaction that includes my wallet address and the address that receiver gave me, once the transaction is made, the receiver cannot see the original address of my wallet, the 3rd party cannot see the amounts or addresses in the transaction and the receiver can move the money to a different address and I would have no way of figuring out that happened. Similarly, receiver can send me back the amount and I would have no idea from which wallet address it came.
We may joke all we want about it, but there are still laws in place and we need to respect them.
Example: https://oasisprotocol.org/
Also, the fact that it's possible to interact with dapps without going through centralized servers it means that it's much harder to get metadata (ex. IP) about who performed a specific action.
This would require more than just a mobile device, however. Perhaps a rooted Android device could self-host an Ethereum node, although your battery life may take a hit.
I think there are other chains and wallets that are designed around mobile use cases, which make it easier than on Ethereum to sync the whole chain, or use technical means to mediate the need to do so.
https://ethereum.org/en/developers/docs/nodes-and-clients/ru...
https://docs.flashbots.net/flashbots-protect/rpc/quick-start...