HNHacker News
TopNewBestAskShowJobs

Cider9986

9,234 karma · joined January 16, 2026

SimpleX: https://smp17.simplex.im/a#GFPITRU-oDdr_NvxpeptnC9ldhlSQnrEvoggS7dQNFs

Fed count: 1

cider9986@protonmail.com

Spam count: 6

submissionscomments
Cider9986··on Ask HN: What are you working on? (September 2026)
How does it compare to Fluxer and Stoat?
Cider9986··on Ask HN: What are you working on? (September 2026)
Should I try BJJ?
Cider9986··on Ask HN: What are you working on? (September 2026)
That's cool. How are you gonna get it in the hands of people that would need it?
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
And WhatsApp is E2EE with the same protocol so I don't see the big deal.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Claims without evidence can be dismissed without evidence.

Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.

If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?

They are the largest messenger that has E2EE backups by default.

Cider9986··on The Coming War on General Computation (2011)
Monero is the opposite. Everyone can mine on their CPU and just like most cryptocurrencies, it makes you your own bank.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want.

Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.

It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).

You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.

Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-...

Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Here's an article saying that: https://aboutsignal.com/news/signal-allows-android-phones-to...
Cider9986··on Mark Zuckerberg: "Cambridge Analytica" (2017)
Xcancel is nitter.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Why? Just raise the prices if they get more spam on non-google payments.

I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.

Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
GrapheneOS is more well-roundedly private than any desktop OS.

Competition is Qubes but that has usability issues and does not have good hardware security.

Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Hopefully they eventually make a way to pay without it.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Likely soon.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
I'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Ah, I thought you meant using google play to do the payments to prevent spam unrelated to the cost. I know they are costing something.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
It says something about Play Billing being used specifically to mitigate spam?

I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.

Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.

They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.

Cider9986··on Mark Zuckerberg: "Cambridge Analytica" (2017)
You can't see comments without signing in and there's dickovers so it's nice to have a privacy respecting alternative.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
I'm talking about using play services or Apple's version. Signal falls back to a WebSocket if you don't have play services installed.
Cider9986··on Registration without a phone number on Signal will use zero-knowledge proofs
Molly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal.

In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.

I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..

Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.

Cider9986··on How Trail of Bits helps verify the integrity of Signal chats
They added that BS and then didn't do anything with it.

Molly is going to add a Monero integration while also having various other advantages.

They don't accept crypto donations directly or accept them for their backups so I assume they wont for registration.

Cider9986··on Mark Zuckerberg: "Cambridge Analytica" (2017)
Faster captcha: https://nitter.privacyredirect.com/TechEmails/status/2099214...
Cider9986··on Making Startups Powerful
OpenAI Airbnb Stripe Coinbase DoorDash Scale AI Dropbox Reddit Instacart GitLab Kalshi Replit Twitch

These are the companies advertised on ycombinator.com. The only one I like is GitLab which I'm neutral about. All other are companies I dislike.

Cider9986··on Revolut confirms customer data breach through fake government requests
Are there any banks that are good at security? Obviously none have any privacy.
Cider9986··on Flock worker calls police on reporter filming public camera installation
We never see, "Flock (YC S17) Is Hiring an Engineer of Mass Surveillance" on the jobs.
Cider9986··on Data collected by cars and sold to third parties
Apparently Rivians can be prevented from doing this:

Can I disable all data collection from my vehicle?

https://news.ycombinator.com/item?id=47967786

Cider9986··on google.com/goto: Google's anti-scraping update
I've never seen anything crypto related once I set up the browser. What happened wasn't a MITM but they fixed it, right?

It's the only recommended Chromium browser by Privacy Guides. https://www.privacyguides.org/en/desktop-browsers/#brave

Cider9986··on Waymo pulls over, calls cops on juvenile riders who had 'ghost gun"
Guns don't cause violence. Just look at New Hampshire–lots of guns, low crime or violence.

Freedom is more important when we already have safety. People are trying to scare us into thinking we are unsafe so they can take away our freedom. We are very safe.

Cider9986··on Waymo pulls over, calls cops on juvenile riders who had 'ghost gun"
I agree we should also add live facial recognition to train stations.

No expectation of privacy in public does not mean we should eliminate privacy from public areas or allow our government to engage in mass surveillance.

Cider9986··on How Trail of Bits helps verify the integrity of Signal chats
> Lol how is that any better at all?

They are [1] implementing unlinkable payments so all that is known by credit card is that you purchased Signal and Signal doesn't know which credit card goes with which account.

>Signal is an obvious honeypot.

Claims without evidence can be dismissed without evidence. You might say they don't do enough to protect metadata privacy but it was never made to be an anonymous messenger, it was made to be a private messenger. You can easily check the end-to-end encryption in the code (reproducible builds on all platforms except iOS BTW!). This person audited Signal recently [2].

>They make no money and have no plans to.

They make money from donations and paid backups and they might make money from paid accounts.

[1] https://github.com/signalapp/Signal-Android/commit/7da3357b5...

[2] https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...

← PreviousPage 5 of 34Next →