When I talk about de-anonymizing the user, I mean that Google Play has already identified the user of the device. Then they can spy on the Signal app to try to identify the Signal account.
But also, regarding ZKP, afaik their ZKP doesn’t account for timing attacks. Signal can log when each account was made, and collude with Google to figure out which payments correspond to which accounts
When I talk about de-anonymizing the user, I mean that Google Play has already identified the user of the device. Then they can spy on the Signal app to try to identify the Signal account.
But also, regarding ZKP, afaik their ZKP doesn’t account for timing attacks. Signal can log when each account was made, and collude with Google to figure out which payments correspond to which accounts
Also, is that supposedly ZKP payment method something verified, audited and, more important, open sourced? It’s Google, so I’m 101% that no.