1

We’re releasing the Signal 8.28 beta soon. If you’re interested in participating, join the beta group here.

Share your feedback on the latest changes:

Now you can optionally register for Signal without a phone number. Phone-numberless registration requires a small one-time fee to help prevent spam, but this in-app purchase is never directly associated with the new Signal account. We sincerely appreciate your help beta testing this new feature!

Complete list of new commits since 8.27.1:

https://github.com/signalapp/Signal-Android/compare/v8.27.1…main

Thank you for being a beta tester!


This release introduces phonenumberless registration, which I know has been a long-requested feature! I’m sure there’s a lot of questions, so I’ll give people a brief rundown of how it works.

  1. During registration, you can choose to register without a phone number
  2. If you do, you will be prompted to pay a one-time fee of $3 USD (per country prices can differ) via an in-app purchase to get an account. The payment uses the same zero-knowledge proofs our donation system uses so that there is no link between your payment and your account.
  3. You’ll be given an Account Id and Account Key. You can think of this as a username and password. We highly encourage you to save the details to a password manager (and the UX pushes you towards doing so), because if you lose them, your account is gone. There is no other recovery mechanism. There is no way to get your account back if you lose either of these pieces of information.
  4. You can add an optional username. Note that if you choose not to add a username, your account will be completely unreachable – the only chats you will be able to participate in are the ones you start yourself.
  5. And then you finish registration like normal! Profile info and whatnot. You’ll notice there’s no PIN, because there’s no need – the Account Key replaces the need for a PIN.

After registration, you also have the option to go to Settings → Account and add a two-factor auth method. This serves as an additional layer of protection against phishing and account theft. In this release, we just have TOTP (i.e. Google Authenticator and similar authenticator apps), but we will be adding passkey support shortly (which includes hardware keys).

It’s important to note that just like your AccountId/AccountKey, if you were to lose access to all of your second factors, your account will be permanently locked. There is no recovery mechanism. For that reason, if you do want to add one, I recommend adding multiple.

Anticipated FAQ

Why does this cost money?

Spammers, unfortunately. If it was free, spammers would acquire massive numbers of these accounts and ruin our network. This was the most reasonable way we could think of to prevent spammers. Hopefully we chose the right price, but if these accounts somehow become a spam vector, we may have to increase the price in the future.

Can I buy an account on a device that has no Play Services?

Not yet. We have plans to add more payment methods, but currently only offer Play Store in-app payments, which requires Play Services.

Can I remove a number from my existing account?

Not right now, but possibly in the future! We’re thinking through the implications still.

Can I add two-factor to my numbered account?

Not currently, but we’re planning to add support!

New Version: 8.28.0 (175100)

Available soon via Obtainium or the Google Play Store

Localization changes

3

Super exciting! Is TOTP also available for numbered accounts, or will it be in the future? Same question for passkeys and hardware keys.

4

Not currently, but we plan to! (updated FAQ)

Can I be able? What? :sweat_smile:

6

Will there be an option to switch between accounts?

That is amazing!

Will we be able to add a username and then remove it again?

9

Given my current situation, I want to restore my cloud backup to a numberless account. Would that be possible? You can do this with a local backup by backing up your data, then restoring on another account outright. Would be interesting to see if this is possible.

I think the following would have to be true:

If you have a cloud backup for a number or account, you should be able to attempt a restore from the number and backup passphrase by indicating the number initially and then entering the passphrase.

Up to this point it would be the same as the current flow.

I’ve found a mistake in the current flow as I am attempting to restore my cloud backup on the account that is locked. When going through the restore cloud backup flow, it indicates a verification code will be sent, but the next screen follows up with a request for your backup passphrase.

I believe that if successful, it should restore outright without asking for the SMS code, right? Unless the account has received a registration attempt from elsewhere.

Another issue: I backed out of entering the passphrase to return to the number entry screen. After selecting next, I am now asked for an SMS code. So there seems to be an issue with backing out from this screen. To get the recovery key entry page, I had to back out to the transfer options select screen, and select Signal Cloud Backup again.

My following question is, does this recovery process check against SVR? Because, my passphrase was saved in my password manager and has not changed, and I am returned an incorrect recovery key error. Is the PIN sync error preventing me now from recovering my account outright and incorrectly reporting the wrong backup key? I don’t think it’s actually wrong. I have a habit of saving my key history in my backups in case something goes wrong.

https://debuglogs.org/android/8.28.0/3685baab38202e5b5273ef95aff48cad14133f2ccad9a714b06d766a55de04e7

Also, I haven’t even entered a registration SMS code and I’ve already triggered a safety number change just by trying to restore from the cloud backup, even though it was unsuccessful :)

It does not seem as though the feature flag for numberless registration has been flipped

10

Same here. The registration screen asks for a phone number without offering alternatives on GrapheneOS with installed play services

11

Is there any chance of being able to pay with cash in the future, similar to what Mullvad VPN lets you do? This would be the most private option imo.

12

Well this is annoying, I definitely flipped the flag last night, but I fear I must not have committed it or something, because I don’t see it in the public repo. I will fix it!

We don’t have any immediate plans for multi-account.

Yep!

Unfortunately not. Remote backups are tied to an ACI, and making a new numberless account will always give you a new ACI.

13

Hopefully you could retain phone number for numberless accounts as an optional identifier so we could have the best of two worlds: easy discoverability for people who want it but without account being dependent of phone numbers and better anonymity for people who don’t want to use numbers.

Right now authoritarian government can easily prevent people from using Signal by blocking SMS verification codes. Won’t they be able to just as easily block payments for Signal and render numberless accounts equally useless for people who waited for numberless accounts just for that reason?

With Google involvement, yes, or by Google themselves in sanctioned countries.

15

IMHO the signal login purchase screen should explain that the fee is intended to protect against spam accounts, and not to generate more income.

Something like “By requiring a small one time fee, Signal can offer enhanced anonymity, while keeping the platform safe for everyone.” or “The registration fee helps to protect against spam and phishing accounts on our platform.”

Or to make it a bit less prominent, you could add a “:information_source: Why does this cost money?” and show a more detailed bottom sheet / link to the FAQ

16

I believe the end goal is to have a phone number be an attribute of an account that could be added or removed, but I’m not sure on the timeline of when we’ll get to that. I think for now we’re just letting people create new accounts without a number. Although it is worth noting that if you have a numered account, you can always disable phone number discoverability to make it so people can’t contact you by number, and you can turn that on and off at your leisure.

I think there are a lot of reasons people want numberless accounts. I agree that this current iteration will not work for everyone. We have some plans to accommodate these situations in the future though.

Yeah, in-app explanations are always hard because you have such limited real estate. It often feels like you have around a single sentence to communicate anything you want to communicate :) We do link out to support content in that flow, and that might be a better place for us to put something like that.

17

That’s what I thought. So it means it would be useless for people who potentially need secure and private communications most.

Hopefully in the future it’ll change as Grayson suggests.

18

Latest release (8.28.1) on github/obtainium should have numberless registration properly enabled :slight_smile:

Just until other payments get implemented. Plus, it’ll already help in countries where the play store doesn’t ban Signal, but there are still SMS blockades. It’ll also help with TWILIO issues that have nothing to do with the country.

I think it’s still a win. :)

New Version: 8.28.1 (175200)

Available soon via Obtainium or the Google Play Store

Localization changes