215
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 16 Sep 2026
215 points (98.6% liked)
Privacy
6187 readers
1 users here now
Welcome! This is a community for all those who are interested in protecting their privacy.
Rules
PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!
- Be civil and no prejudice
- Don't promote big-tech software
- No apathy and defeatism for privacy (i.e. "They already have my data, why bother?")
- No reposting of news that was already posted
- No crypto, blockchain, NFTs
- No Xitter links (if absolutely necessary, use xcancel)
Related communities:
Some of these are only vaguely related, but great communities.
- !opensource@programming.dev
- !selfhosting@slrpnk.net / !selfhosted@lemmy.world
- !piracy@lemmy.dbzer0.com
- !drm@lemmy.dbzer0.com
founded 2 years ago
MODERATORS
Signal knows the creation time of your account.
Google knows the timestamps of every transaction made through Play Services.
Law enforcement wants to deanonymize an account and subpoenas Signal for the creation time of the account, which Signal will provide them.
Law enforcement subpoenas Google for the records of all Play Services users who paid for Signal Login at that time, plus or minus a few minutes.
Law enforcement now has a shortlist of suspects. If Signal Login is paid for by 1 million users per year (unlikely) then that's one user every 30 seconds on average. A 5 minute window of time will be a list of 10 individuals, identified by their payment details and Google account.
They could, for the time being, do account creation in bulk perhaps at infrequent intervals. Somewhat annoying for users, but would provide at least a bit more obscurity.
I've looked at unsealed records provided by the Signal Foundation, and they definitely have the account creation and last accessed date... But besides that, is there really any information authorities can glean from this? Or is it simply the issue that this leaves users at square one, if they're trying to avoid connecting an identity (be it phone, or Google, which generally requires a phone) to it?
For me, I see this as a potential boon for simply having a second account without having to go through the rigmarole of maintaining an extra SIM card.